-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sitracker-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sitracker-14.1-jessie-i386.iso cd9170fb7981822f34d1528262d2ac56 $ sha1sum turnkey-sitracker-14.1-jessie-i386.iso f32cf45cb338fd8f8032fdf5dd76fad7ef744527 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNJuMH/24L9aKgJsWj5j7aH4S6aU5T aXlpTToBJNYXrdZO5TJgn0JSuxpoTYGP/bPrhuHf76tEoZmZx6/xC2OwXs6c6zHG tVch3m+FrV5fC7e7Zs3L9nz9ygdlZpuHSWUSplLogoPQrHd4bY/jyKCxxSz9n0tE zv1y3n4YoCqegSRj0rpn7i5CJGWuner3RwEG7Ba1Z+xS+0zl3LRhJWwrrohzrbxJ epM9gDyaWZwf+sx0v60WzoXUDHlYUc4ItdDuv809HGNbxMc6CgwYy9TjdYjy+jzF I5193RphtOeMXuBn7aDsTr9fYvMc76hL8ud7bOroA7r2vokI6bdpoX4CNTedjfs= =l7hL -----END PGP SIGNATURE-----