-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-ghost_14.1-1_amd64.tar.gz.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-ghost_14.1-1_amd64.tar.gz ecbce5657cb162a6abb0666f93c2b12c $ sha1sum debian-8-turnkey-ghost_14.1-1_amd64.tar.gz 3c0cd4a05a3fd94dedbd3d1316fff35ae156db4e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXRb5mAAoJEIXCXpWhbrlNUyQH/1zZIWk4Zc/HF54s6tQIivBA mFq3eX6i2Tg50FRiIXokOVcjeJpHBrSdhl1f4S9WW7KSVkBM4qzo1H89iTZ2WeQi PQKrSBNWZ82tN56E3Ha3UfT7WZBtzHzZYBpj/mRgpMPjD6+0G4NB9JDNFJQXXotU prV2qaf5dETxvXBm+Ife6dHjtR3ARjxiJNkNpR7+KBwpLs5lbM137q9tV4sE3gxr gDBFlp7JrTbRYw3N5LCuFOAsKX27/MA+TSHsexkVII77tKzVkyaPIxfoxARHCL4a FT6aZpfvVZxy6lpSggbn4ef9zRWS1/WkA/6OcP68kRrla/2J6JCjD5w0sOof9Fk= =WrXn -----END PGP SIGNATURE-----