-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-typo3-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-typo3-14.1-jessie-amd64.iso 43b83b1d4fe45d97b150934d0bc37429 $ sha1sum turnkey-typo3-14.1-jessie-amd64.iso f697d97e2ca2fcd087e4f270de5c8a9c6ade018d -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP1AAoJEIXCXpWhbrlNon4H/2h/qf+4PsJ5dyKWyiN43Bbx d0b45vWRjUF3Wus0Hzej8PBcCBbDTC1KhOTCTTHi1+XzyoOcjrJOWIkXM4CbePj3 T19vPKCuj1GZXeEaNtqBJj/CmLKSrJt/jsV4k16dmvtTrKuB3l5vQXTh10BDG1B2 4cpVC4LxoxYWMpmV/r4itrtIGnuuzF6aQK6/kjjXD1W/wBLkII10qQryyJcc9bQA bU7R4hKtzLZ+gIJiELJ+rhYIiUVEgBfmWtFXb3zRKSuUAK9efYVGqIArm0lT57j5 eAoj1jsYSn5CChBmNAjDbi1clc9CmDRaD4MLWdQuOvydgvMG/cSZ0KxRH8Txznk= =iiDW -----END PGP SIGNATURE-----