-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-web2py-14.1-jessie-amd64.iso 107b8491264e5d05738f7ac474928306 $ sha1sum turnkey-web2py-14.1-jessie-amd64.iso 67083fd7a0525817bcb5d9dd43c8be45e3548ff7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP1AAoJEIXCXpWhbrlN2LQIAKJaH42Gyj161DVM/Y/U9ylv q0+q70cA8l3bDZC6g+s4hrv5NG5VdicCq0s5HJ06jrimkxIlpVWmkj871GfTn2EW Q05757p3Zj1mKGEF8YaSwgEPTdG3j6thNTl69A+Y/IIffj/dgj0vYyTUW3pDdWhe C54zcBTtVkYvffggpS4cQRTooTSRbqFzS584QgAOuvUsAPP2MTlMWZgaT3P+KAbK I1gC3KD5qnnvr2DSBL/GOWicFld6haJ4r/DX4oNvgzycS/nS6ItTYimT7aryhudX uMd8SiNd1afTyJalZ1cyB4Ij9CLF299mTqrY9dAAWWVv4epUnzbABLwHJ+lIu/k= =CK6b -----END PGP SIGNATURE-----