-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-observium-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-observium-14.0-jessie-amd64.iso 3ac9fe5919b8476e8f03c982b71d94da $ sha1sum turnkey-observium-14.0-jessie-amd64.iso e011247b13dc0eb10f885bede8b81464e46e82ef -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrpAAoJEIXCXpWhbrlNGhMH/2ubX/Duxdmo6JnakNfgz0iA rsAVQAyO6Jk1AXrt4F9am/I3iej2mtM0f9HLKvb7uwoh/UED8zKPAF0I2xNpYTaE ZNE4mzTTcEZUR68HXMYyCFynCSNxiTIn60f0yA7qkBCe+AI8U/yhusZD18cFEatV nWhg+lF4uBvWr08iFvIxPXq3nBX58DvGEFs7i1/JYjWm3vLdmdHI69jIrW3GCbRN 3GKLiBgylG06HrcqoQhKhsgufuv9O9kYhEH942RAaaTfFPbc21MA4KrJbdqojspo frejBIicK5bTrhIRRU0gU861V3Ha9Bmq/dN5xmKSJVj9BWVZ9tVU01leUzxKIXI= =5/D8 -----END PGP SIGNATURE-----