-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-b2evolution-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-b2evolution-14.1-jessie-amd64.iso b3a306fc47309c8335399ce09b56ccb4 $ sha1sum turnkey-b2evolution-14.1-jessie-amd64.iso d68ae34849995e230882c79b4d770cb15761acbf -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPwAAoJEIXCXpWhbrlN05oH/i1AHwRm3XEIZQCnpbVKqYvx U6xIEQjSlAQPA+aY4rbsYxziZud5ZZVc+ziHAn/xJ/a3vndDD+796RuNu7tOyZcI +nCLoyye9nkD9MrdNSdS9NCrcIPmNLZ7LgYK3by76uXp9j2yVCS9eDfN2GvbtXb4 KvubOR7l+4myYDVvlPb+fa5ClB5YMaldZzwwPVvpWzahRCxSReg+40nJBhH8tIjT 3gAOUPo5K7blOWj4KmhkHUENSav19AbghshOXwIvVP+ONk20aFvhyITI2rBmv9Hk HsHtevaAy3GU1GPybYHIEj8UTk277xwNqGrIEyTQwgJ9wSQaptrnn30i9dL6gFo= =IC98 -----END PGP SIGNATURE-----