-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mibew-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mibew-14.0-jessie-amd64.iso 1ec70ccf23cde00dfc224e8493f2697f $ sha1sum turnkey-mibew-14.0-jessie-amd64.iso 9c8b25ef247dd1bc6d2862d7bb64e467e271f076 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrpAAoJEIXCXpWhbrlNnCcIALdkQhuMn7ia9Mn56sox9s7a jAcd9JzPcn6DeYYvofP2JBqFBpNCGm+dP4+2erhQbp3SssbNybYcVOXhV5ZkmpUk O5NBKlKdOv4HGbzo4SFyVDmKioa63iWC3zOGkj9qlnrwZ/bst9EL5EsJ8GZ3HfU6 1yrM1JKGUtf0ZJH3II2naOwXuzm9sGV/Md9wi/r8dZGrCoAvMYeMRw28V39YV1zl v/eg/seClTYsIS7J+fG8uHEG4vMphf1Q9mXxPyLdcisHm1HfBcY0wH+J5vp4qtZO fe+wLJFdTCvEKT5hKAYqv3iwocPbPzP0xDij33/Orq1Mz02xW+OXRgoEQl1hP8o= =/2K/ -----END PGP SIGNATURE-----