-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-oscommerce-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-oscommerce-14.1-jessie-amd64.iso f6cff4f0eb0a994b32a5ca5a854b79e8 $ sha1sum turnkey-oscommerce-14.1-jessie-amd64.iso c4af94fba28274d096b0d8e20cae5922632c362e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPzAAoJEIXCXpWhbrlN6C8H/14wW5Hy67DpvHvT6jEkN/uE lr/T1M952FMcTe3t0OQsYbiL0YGVR0G64DErb19MuhX4T9eYFiQUgFCfthaOGjVM oUyz7k460sJA1eRkpeDQJHaGmBah1AmHHjmgtHh2/1WpvEYzyzbjAi0JqyktuMV0 CCDLO6CRVqlnpxnIayKtejgizMELC7qo/ZWyo29eSvfcRHbJWVbKQejrUlDqZa9h ikMpDwsL9F48ApFMRGqHRKWfvh+9FUFVwQmSlUzSpfY9FP/dQn24eGcavCgZop7a jhJrIlgSPO1cAIT1fTQSzrsob/pXlJbP8p7gcJ3FaYKlV3Y2rQ1EcK1zgXkEdwM= =X5YL -----END PGP SIGNATURE-----