-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-laravel-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-laravel-14.0-jessie-amd64-xen.tar.bz2 4ad02cd4999c12812901ce65fa8dce87 $ sha1sum turnkey-laravel-14.0-jessie-amd64-xen.tar.bz2 c304ee59709b9908effe85daa5da70c9f023c12e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiBAAoJEIXCXpWhbrlNVHMH/2S1UDf6P3nhY4RMjqlwE838 QSqJuz+vnJ9jQ3NdU7ELsrqjI7199Cd2D/mLK0EC+QqeGBsPpffN2n/XrilQ3gD6 ko/1I705z4LQIlp3FgyVVRf01rtqr1qD78oqpw/F/VNn2cs9280VC0J1Uszp953O SLo8hIW58XeZsMwDBpEPIZZzan+mjZZjrjOuGDk+ewF13uaSRFUuDL+lwYbkZz9P 9tG3Q/MQAs381r8eq8GmMoJuu3TKLLkWkLAKovPF6wYW/EYASOC1IDkQCPW8FkIw VlqkEaFaFr6azHCr8CDWynvqoZ16Rbn1saQPhcd0Ys8G9OugG1HjB3WRtOgiAjI= =yziw -----END PGP SIGNATURE-----