-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-pligg-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-pligg-14.0-jessie-amd64-xen.tar.bz2 cd30a4c6a50f9a61393c3d0eed9a7756 $ sha1sum turnkey-pligg-14.0-jessie-amd64-xen.tar.bz2 7f57978e9033a5f899aa0668c590d248e7c284a5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiCAAoJEIXCXpWhbrlNQE0IAK6VB4g5spDDtFcZJy0Lr2s9 /kd3i6lgfUD+9C+s4vu43rGUWO6rjrVn1KsDheVWSs2DVBHA93FC+tk5T4DFcY8i WWnBpo+8AmRWGR2iFAsWYVNqftaB/KgyXhJVf/7xp+qnwsT6jE/otBjBSo+FYJdj 6mPWxprm0M+NCOlEdfrTWQxL8Lc9B+juGLVxdOhzZ6KQFr2bWETbIosSdYwU6pvD j2bkfjzvz08na/WUz+HMmRuV0RqW0SYo1I6WbqQN3RECDZxpKx0wsP8obXlZgWz8 2c6KCTkdW46mLWkSji37F8Nx8THtlIASrGp9rZmHy+LXhoYFKnYFFl9tIcl7Crw= =qyuB -----END PGP SIGNATURE-----