-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal7-14.1-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-drupal7-14.1-jessie-amd64-xen.tar.bz2 1fcfe7af52aa9138217046ad889d6b36 $ sha1sum turnkey-drupal7-14.1-jessie-amd64-xen.tar.bz2 c4f7a103ce8d395252543b065ba07fa995348e35 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnyAAoJEIXCXpWhbrlNmLMH/RlKlhEVZ04as3mgb3PVRDgz GooWS8s1r4eKJq8yZno8EbU+kCGSNM4iATRBfnvmHH7KINRQvoBEWm1pXFW1rW8H wImm8nd3JnhRo467RqXs8s4RRIRDljBJlKF5XDYbwoSTymt0cODucZZpFpGUoKur C7ElbIQXeOpzXAftOvRnsuxkH5Y0xQf0GTXVNXtcdH5ZwTbxd5dg1ZNaLndQAfUP EFpaGP0jwrc90MIHHWDqiIX1l0snm5yzn1dRhrG956hYrfGaQXpjtC4YRnqSJbzB MjDWxrxCWuaS8gk615O5VNVONpO+JPmcIQN3n4rBYTHRROu5EMxzBl4Crnpn5f8= =0jpX -----END PGP SIGNATURE-----