-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-dokuwiki-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-dokuwiki-14.1-jessie-amd64.iso 884f1dd4e1d6fa8ae03e6267cebf015e $ sha1sum turnkey-dokuwiki-14.1-jessie-amd64.iso 61b9a81ada13d834df1ee5d0e8519cd94f900d03 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNoNQH/3OBeBOmZ4U2nFJ1DBUO71co +ZIXnxTLyQiQxGII28riDQEBC8oYhaa9RXXtKLSS0qOjy5Z4/BYE91y8i691fDsg 64FY0bo0bOIkitkPeNn+NNIuPs79TKE7pWk33XIBIKTcjfFm3qEGKPQToBHgYsaA fu+fs1o+1UGHgAXridUdcYpiguoPv6soON2DxT5Psykmk3osIw8ZWj4wbKNLhxtG AZ5VWdV1LG+7jKP1ki/1TMS4guBLd5R1gPa9k/YllZxyN3KBkoI0wTf7IKB/CZGu qckKMAUjXMlyFBtZ3fG2MME5e/obtosogENXBMy67mgoWvuusjXlWTeebWh/LLA= =wA+t -----END PGP SIGNATURE-----