-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-14.1-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-bugzilla-14.1-jessie-amd64-xen.tar.bz2 2d21e1e76c36981f6ee300e346b3ae99 $ sha1sum turnkey-bugzilla-14.1-jessie-amd64-xen.tar.bz2 4df0b566e503b6e2ab52555db99ceea8a18469cf -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnwAAoJEIXCXpWhbrlN7oYIAI0vuSqImYu5v7It68z2368A 9eQYjl2Uv8KIXVH+yoOPdzx5NtiWoGBsyFK0vJQ40C3aFjAJAj7EAGqmBa6fnoaz ue8apl4jLHTpSQTwazIp+iWEqN4bWRvJLF4qwOXX/BCmVL43Ma9jz8dtHwY7gEq8 F3ItTBOCdAjxRjrckyms9fDv/y/W0z32AHB/+73yODqL9ZDcoq15jNeEbkWx+Dda NcUiFfcimjR6ILquJCIzc5W4nLvKSXa8Fxz0HeqRrTRGntT2kOMTJutYFhif88W8 gqL4GVCNzrsVff0hFh0Gwy8u1rh1pmc1i5n3L/N36UiKW3FIkI9IPt6KUVmFuT4= =/2zz -----END PGP SIGNATURE-----