-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mambo-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mambo-14.0-jessie-amd64-xen.tar.bz2 99e6b48034a5b5e769eebde43d27dc4e $ sha1sum turnkey-mambo-14.0-jessie-amd64-xen.tar.bz2 26658d29441e5b10ba4d15ddff4772a92f9e65ee -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiBAAoJEIXCXpWhbrlN6aIH/Rqf+sLRHqXyoolKnVAXXGn0 PaeaZMadG2AqP5+6uFZUE9VFE+J880rYTKZY5t7iVsj/6i/R02dEZLdoZDMX+0YC uTmJ4WIW4jAjgIGRBkTKMfDgY5WES87uRzHMd+WphWtDx5oMMUY2OYDzvxQtYau+ viz0t7LNonAK/Qs677YgNIQT3QNPDLjqEwB0fuZ3G3sqowusTJQOtIXTzEd4z8hM Nd2lTwTo9SOf40YBoAUqHAjJrNlIaRcKWOhcK/933ld0BMZ5aAJ1rgUnQrG/zM6Z jnYlar7AjM0gfPNFlfDe6Xsl+O3G6CPD3IIpOKtPem8NmHTlCEIuLBTa7q1s46g= =mX24 -----END PGP SIGNATURE-----