-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-simplemachines-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-simplemachines-14.1-jessie-i386.iso 1c60ff70db3d97b25065780f342a7c70 $ sha1sum turnkey-simplemachines-14.1-jessie-i386.iso 4141bf2c00f12dcc1e5d7c36d5e2f73cbe5edfe8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlN5bAH/jiiKc0vZcZ5a87zvlG6GQPq OjVatqD48GedSlJsArXYJIZ3ShT0ZYXz+2cHJF8P70Fu1WJNrjG8o9ZXNDiprf8C NpHRyhfUehnkZNt4dQBrIR0Z3R8uLGJBqewJnITDCu41Q8JNPq/cTjvR7hwL6UC+ Z/Yso5ojPKw2wGybuAvso7WcRml0eNn3TeIomPQmnCSuP1a8jPPxeDBDsCVCe4Bg pox0TInDspbP+4rsi/LZ+B7GPVBg8r5zLZxf9gs0YKMavbix+lFybe9GA4IeibAg gP6z96LKYraVBtCo3FP2dVYj0LoyUKQoNBBH8JhZsNihpmAm1qnaDJkpJyemNEk= =VbM7 -----END PGP SIGNATURE-----