-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ushahidi-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-ushahidi-14.0-jessie-amd64-xen.tar.bz2 7fc3d59e87a1ac1a726df2202cca6b1d $ sha1sum turnkey-ushahidi-14.0-jessie-amd64-xen.tar.bz2 468fa35f62e88711ea39c1a37f5d341d884eada4 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiDAAoJEIXCXpWhbrlNMesH/0MQZ7PNSdSiBsJRCKk06zHL rhe4071vZgp4nTJbGP54wJIsMlqJn34Z09bwA3Qz293L5YUBhWe4mXuo4uTjNgU3 loLz9g4Ibut/UZIbrYnUgiWFhTr+uIKJNxG7+lBiYElrVHT1TWVf+TjO9KiOHbF5 VSSphVKxVk8btoMfYFnows2fyTBN6is41xz6nqdj4Ebf4aCGfuB2jnZVtVNJ2BId RspAu6Nnbpm7/FNtWhqMm/hoafRGPLhdbKojVKNiOuWS4dQCAPoEokJ7OvS1E2Gl FFUbZaQhrTGTk6NtzCrBKTk7sC+JqxcJvAzi/VYsCDGN4KyU6c6AxD4KfhqTWJc= =qajJ -----END PGP SIGNATURE-----