-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-torrentserver-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-torrentserver-14.1-jessie-amd64.iso 5c10d8a1d9a08cf6839e67fcbd494556 $ sha1sum turnkey-torrentserver-14.1-jessie-amd64.iso c52a1980bb4f6d1d81f5de3ea3171a1b76ac451a -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNS0kIALLMqZhn9S4lyVTR5YibgWRi LWar8wtrWGf2Cams751+W9yoFowIWHjzuLFNWkRE2BDpufUYos9u1lhJwzDtwPA3 x5G0PgE8coMBFrJzh3pxwdA2QkxJw5xirz2NeQyGcxIQ9dujIgLE8ddDfdcD8sxV 4Fx8UgfxIR766crcYiEPsTQqLGsykELqswpUji0KLq2Fn0ewrcSPyivT4yJQDke8 SPxpvzl//XWY8fz1R3Qoy4jWSzLbmAxQRRgGD55Nu2IttMkr55Fzg1dVWufA4heh yind4lrjhCpa0IxyBQsNMp7/EOBCshxVpDvWersZNQ6DKcVaHf2y7PV2lSsFc9Q= =NJNc -----END PGP SIGNATURE-----