-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-e107-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-e107-14.1-jessie-i386.iso 2d037a79d9bc6a04310dbf21e719bff5 $ sha1sum turnkey-e107-14.1-jessie-i386.iso 9dd9b08fa51dce3647d5a18da2d7e90e91a5c8bd -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlN7yAH/Rd/r/aQGdnd01XuCTfUWubK uhH2WgzFatAI9N8NN+k6L0/c5mPVTsi37oTwy9BrxcvMFMvuzbD9N3iqGqhZ+yFQ bAsL+i1qLwTVnYecbz6JyN3DyQuDXBM/SzmJFwOTHJnxnuHMpoiDA099p9UYSOdV qt/CotAy54jslPKxul0y0slMFm+iJlXLOJyk3GCloKvDfVQN/SWKkHA15xtg7bd6 HKgvDctpVTIbZX9apRX2cZmT7Z57zYwy7019WLTLeTz5UZNIhmrFSmG0pvZV7Si1 IL6HFwzWeM6Y68u0XSH4pIVOVrKlKofM0z6hBBdsK3FQUHRlETDE+Xr8KEk2REQ= =6eJ3 -----END PGP SIGNATURE-----