-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-xoops-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-xoops-14.1-jessie-amd64.iso aae4d6a6b2bfd2abfbf5e5cf9ad5d3ae $ sha1sum turnkey-xoops-14.1-jessie-amd64.iso 08475e04b1652945215083a81b3a3fa68274be39 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP1AAoJEIXCXpWhbrlNi+YH/jb61BT+BZeWQyi8A/owmB/n w3LlMlOlm4TwsGMyfHCmY816Fw23IuPEIapQNU6lREdQvLOfUkBC8BqlgdDnovAC pJZ+22w0blorZ+hecPq633741yVHSVhYf1U6G4Fbz3GE7nkEKP4Ch7ahtavZqTqx jfEkJq0ihXqfaStdI8lFSqcgOM0PunfDQpLubDheL2d0LtR1J6QuGXQV46gDi2Un 8Q54krx1gVwANFy14gqcqhPtUmDqNFTDm7TklPMVmVDQxYA0Fyn9to0Nvkmr4Lth JUQo3/pqQRiFjpc6rZRu9AChqVCw9Pr7s7XH/pSDtYYgV6al+U39GgjTGDAki4E= =twO6 -----END PGP SIGNATURE-----