-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-joomla3-14.1-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-joomla3-14.1-jessie-amd64-xen.tar.bz2 9407f09325ac13092727881300e6e4a1 $ sha1sum turnkey-joomla3-14.1-jessie-amd64-xen.tar.bz2 f94f09ca0f7179527c9a388d643f97e383fba135 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn0AAoJEIXCXpWhbrlN0AIH/A98QzMQk5y3N1FqaOfNkLzq 4g366gydYbmHqhuOKh/QNetoFtzZXWF7GXRyjzXQwPGcvidLuC1OJEJnSPyPOu40 nbES26GQ/C7fYjt3i4TEG3Ewz6wrhwGbwxqpj78w9tzV8CzRH+i9Dr/uGIBA1i5X DQLA3CvQySa2v+Q8+MwNURRHPcVZ/aVG0W9SORuLZtppXPxmReyKB3yCFySOA/gO gsGkEhfUWYVSbZzlSvAC2sFEudeSQiTxc71DwJrWZR+0Pw06b30NacIi0v6LGCrq T+CVsA7KjbveqQ0X89Dq6qa0m18EbjwbE1UtBiHyhiO36lBPST+sfPx35Ug4b3g= =USKH -----END PGP SIGNATURE-----