-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-torrentserver-14.0-jessie-amd64-openstack.tar.gz.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-torrentserver-14.0-jessie-amd64-openstack.tar.gz 373df0cc132cd221cc3a66c3ebfc2781 $ sha1sum turnkey-torrentserver-14.0-jessie-amd64-openstack.tar.gz ea49e133c04807e8dce263f24702fa5cf0c883d9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWXYG/AAoJEIXCXpWhbrlN6XYIAJ5Qqt59Vy99M1s7AgWhFNwX ThzF8e3+yPNyDOnGiAkdlDtQDQp2ikgji/4YI9ccjX4/SgVVn1XHOxowlmK64A4/ Qy6YYQTXlKKnLLOKyhh9fr/SchGlj3tzeVgYBJQvUOtlgqNQR0bkdLEKv/dB9ATG n9ReyY98klvnz+Z5sRDrKqf2iQtnLrRb3ttOl9DN5NFw4XbMsX2kOqbDnluCWq52 VZ8oTbv2Yt4gLv3dXK70s5v4KlquIJoi8s8uGKs9jGSeGM5UJua734w4ozHtM7HV pcib2IZRhp3MTfZVHDmRq6Un8xTvN3wzpOX+hOeuorWaM6oONCmAgcDVKW5J8Wo= =ASxc -----END PGP SIGNATURE-----