-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tkldev-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tkldev-14.1-jessie-i386.iso f8df407c60a0ba000e2cde1330cbc0ff $ sha1sum turnkey-tkldev-14.1-jessie-i386.iso c8d684ffc317c02239e5c136a18c84dc39997fcb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNO94IANdDwwYOilOl8bG0JWbPdjI/ dC2djXR9/E8zb0GdSSiX9jWaaLThmx3Kw/apKAx9J+ftxXBWnl5C4uExgu5SMPA9 IoQPWfL78hCnuOa7uDLSkP/AhmhPYy/ZPVzT4YihL01YXQuIaijlO2lHUlpOyb6k FDCf2b1RQHUqYABgwY/cg14kZNLYFsKnjFTw8dpueaRfYq3Z8H7dUVxjlwDl6VMn fNoiUwdal9RWulz1Es7K6IPeTJ6sN4vEsbtSJP5n72mYRSLqCXEoUsSix0QlsDLR QuJVR5842znjwTpy9rcKxn6kQtNOPYypgwMakLbsoO0XqwoJKHgz3ef81UdaFT8= =c2DB -----END PGP SIGNATURE-----