-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mongodb-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mongodb-14.1-jessie-amd64.iso 0733ad2eef1d0c36974a68fb47848969 $ sha1sum turnkey-mongodb-14.1-jessie-amd64.iso d50e2a076a0fe066d12cb77ed930bbaf3aa0e6dc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlN8VEH/AksZ7OgiEI9j7XN6amE3WMz llTv7AAGD4UR6upq+yICUwX1fa9v8agiJQhSHgGxett/ZI3Myp1EhQlQaeNAXZD7 JxO7R+V80muR5j3cJ1jIQV5HE4OTP7fup9h6rxZLuzoRN+m/T0Fhkaex9IBNT6B9 fIuMS7h5jn0Qq7iFUCVTWsJBO5xyOaRUBDMiUVwgQXq8FKMDdp+pxxHTZFy7paj6 vQG/1/+JkmI4KmJztuyLTMFxE76nZdWn3I/RYVBniqkWMr6/V55jV28dZBxymAbQ VcSwuXIiuSA+52yOrhk/pMz85ynJXOfH5nDFosaJVIDNZWuFss4vKQokOdvSDqE= =Gbqx -----END PGP SIGNATURE-----