-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mahara-14.0-jessie-amd64-xen.tar.bz2 657a83d695bd65cb5f3485345574de34 $ sha1sum turnkey-mahara-14.0-jessie-amd64-xen.tar.bz2 ab174a1fd7e628025e5870c8452a9ab6cacd7bb5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiBAAoJEIXCXpWhbrlN23kIAJtaAKTlJ+qKlY8ahVaCSq54 u8qDIkH96BPNrjs/r902SJb/gW/lM0y2aSVXdpQpgDr5hJC0HrQAvC7ajZbkS+6m ptmI7v5qKi/AhwTsHBO8+ePow+RXUK8RegtXXao6CPSVEEvQoHfLEmUNDR1W66x6 gfxGR1slRU6u264c1JpL78gXC3WKrgJ7X91PgiVd/LpVBQQ4e/QZeC8yMC5C9EVP FQrqb5NzIvbFcps9loawWk7lRSU/bdyaO5KqOm8ehjQ5OmRtKdRZq6qdxhEHs8TF vGGW4KYr0aKBjfnY1qtYwqUoU/7p7bZD23RF0uuHlFZpLZdDSVsrdAWzxX+BL2Q= =PX7o -----END PGP SIGNATURE-----