-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-limesurvey-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-limesurvey-14.1-jessie-amd64.iso e2e5c5134e783b6c842c17d9a70d9057 $ sha1sum turnkey-limesurvey-14.1-jessie-amd64.iso 85355116af6418c6287a0edd9a3e3b3f965f64ee -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlN7uUIANBx8oulK3k66Xm56hH/oS59 qjUwJ5Dy31Dd9S0rWdVm+6tlhXvWG7ZArrveZtdhQu18h6GVk/ga4c+gGuJkI7ea zzYlkfcViuLgJQJAr/+OPanl3ZqtEFf9JOBryGOsdSZ1TOJuw0gh2AloXqMgwTlX ZtXFsHFu3PiD0tEnNJVA7PU05PIlXs6K1D48GvOLiNrwV94Tami+tKEqKaBqhUze TAPaPD0J7+kz8ja5T9sHiUgcnRPBhRF0O4H4Q8/+poKkeh0rlms001+m9Jh0cLn0 f5TQRM81eqyiY+6fZE78wrEgKG4tEF+qNAOk0iJxF9NqB8hZD4tOM5xN8RWK68c= =UpOb -----END PGP SIGNATURE-----