-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tracks-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tracks-14.0-jessie-amd64.iso ac6f5fcbe699bf76807c453d90046b4a $ sha1sum turnkey-tracks-14.0-jessie-amd64.iso bf0db91b1ad06ce568eae0e0bd848cb1b66d3832 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrqAAoJEIXCXpWhbrlN4MMH/1whTqONAsKOi0C0rdac4XmY Ynj5v7pOvu9wczs2wEHJqw49joTBywc9ZwYv68h1G70YGAJlMCIKDp9QsXpG2RrD t2KRKplekDUESpZs56FQo5UjfKlhbp/aDl80iyaTeSakjYaXyWSELrS8RGodYU5g lQBlCp0AU82w+Y0jyCozR4KTSsNal+CDmJguLqXrRBA6scyaIEILrKonReHkRkyA fz9qU59r3++aUF0Cogkjpa3KWXs0gn65MgjAXkp4ENiWX1y7+fADoCLRIDq36RsU mfAya13OlKTHQKg4EsMpM7YmIP/XIoxiODQNC3HEamogjIsDLhwsQ8dVgO4NZ5A= =KWff -----END PGP SIGNATURE-----