-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-torrentserver-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-torrentserver-14.1-jessie-i386.iso 0e27e8d1114e972a9dfab9c11043a626 $ sha1sum turnkey-torrentserver-14.1-jessie-i386.iso 0ad342cd09f482a6ebd86709db8885bcce34d495 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNCCAIALkOOm3kBmlkOMbwzanXKKuF AJcsm6BaqIn5L51pIoHWBW8ztnCAQCb8VagYJx1PmGVLT9PXG6WpDPtFlpYmgKuP 9mYp1VtZaBAToU1YOZpzr1h/t/guaNzsyhtfoBV/haurGL3Vo41Qc3ovVrzjavLc a6CXrXLcKh+LBjFiPbk4OR/qstH9bldKxzCJ2Yr6Oo51pTeT836BldIA8NFaHiON gTAT2k3QoDhMvlJvPQE2AXltIirqNbBctHom9TZ4i4ZTDDRrUTnfI1LYo0RTkA7n SvXeY6Q1+15FuIAVl6/VuUy91upUt6IHZK9Ifzt+DlDaXLOMP/ALSNthO1DHWxQ= =H2Uz -----END PGP SIGNATURE-----