-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-odoo-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-odoo-14.0-jessie-amd64.iso 30a1cc63e1f95f9d1d0fa5c47d797637 $ sha1sum turnkey-odoo-14.0-jessie-amd64.iso 2bdad3a600061f814dff6f5bca0d946e9fea3bd2 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWL0DfAAoJEIXCXpWhbrlNZHYH/0KbjY8BXTMP7DVuVDOLCdDs QVu21xg62FFTt2tyA9FpiUf9xbAtFbTBczx/aL6Bw8gUbvfoHQPiOFjy9uO2wQDD YKXZUyIeUXFBZqZC9FE7/8VLUvJyn42dQijp8eijpkc1r3PBzDaCPLASTjy4gdFm XGNmA5o6d0JXiEZYSCgiUro+24x2vsn80p5EktMdMmDY0NbOXRN6nXXq50k/Dt0r ikj7FBIXDkwyAEeuruSGog9JTLogG5BmHfuEqonMsRtwCPCgqOab/gaR6PwSYrao uQqf5VIGbigHLdNVk4C7GH2KS8/pBS68xc1+nUqToOOsiyMq5a220GFgU7ADmGI= =xj39 -----END PGP SIGNATURE-----