-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal7-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-drupal7-14.1-jessie-amd64.iso 7e1fa08c9fe6d6e38d4922bf3f7e8fe0 $ sha1sum turnkey-drupal7-14.1-jessie-amd64.iso 8bb0ef43461b782ee3bced37a6c5e554b58b5812 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNDysH/AtuRWrMuT7iaMrNRzZQo84y GIi6Y48gzHUdwqGhAUkOaTgVFuXFMeUCdDopOx6SYUQ8qGNPk8XNk+Lv8STnLV8v 8a5PF4TO8k2lIE0smR6q2QxG+VqNllC/YCO5cJLSbP4MtsYFvaf8lV7focmXUfEF /8l9JWCuB9l1jo1rv1KEe90cZ/7bwlPwBfXYxOjpJ5OFmo46vDYjGdwmpit1DKLM ThCE3w6wESzP9p/CtXgOS1ds8LIch/sGRNya2YW15LQ8lsOGyBSpC++lbMG8KXW1 rQf6PJxOgUnmXrG92bLEvlt9BvLSArRb+5FFfc2Ki60rFjeGJ/AlYoL7kFttwLw= =N15V -----END PGP SIGNATURE-----