-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lighttpd-php-fastcgi-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-lighttpd-php-fastcgi-14.1-jessie-amd64.iso d34d162750ca69232d44dbdd52bf2181 $ sha1sum turnkey-lighttpd-php-fastcgi-14.1-jessie-amd64.iso a4d78d3ca8fd6b064a9399949e73f04eb4580e98 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNKxAH/jCglL4Bwy6yql+JPmC7Md8q QAR3lMKIrkBFIL21Mj05nuzNOURzpsQxwsQaSw9239B4KVaBqC0JGq2ZYzeR1jaf GFXIgVlnXlL2H/vfyA3uQqvKoWGK4oekILvSCCVoiw8YHK/CbnJDKSZiJ97Mpr+W PsYvXhb9EBcWtgyHrh/a2xphAALef9ZRlkjwn1z3U2FAWRbUQEyU+U/wZUGvuXXo J27UWG9Fgkzl8zd0RYddvKwD+I73JGEZMns1/bXYAIg+NNh4HsCUTd5XP8bCxDmw P7FngiDN0TJpeFbz2/CYGWiMOMtkNwiWZaXQmqcoSHXBKN54pF5l6lnGw1TNW1c= =msL4 -----END PGP SIGNATURE-----