-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tkldev-14.0rc3-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tkldev-14.0rc3-jessie-amd64.iso 9fc409dc8abe7616b22b32d39a732eb0 $ sha1sum turnkey-tkldev-14.0rc3-jessie-amd64.iso 39d3ad3de80559d453de4c3a98c83c1120159c9c -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV5sDuAAoJEIXCXpWhbrlNPssH/ApUIuw8XLiU8E4Pgwk+IFc1 eMMUhyWfjf4KsW3+4tZCie6D1hbxA88fdNO52eX2xXpwC/zjbzfkHG+J1duVx9MD MpgR/7J8ye2SRRJAPxseVhKcq0/iHUQZwBzHrmwDRl2re1BauO/EuWIO9omh+VD2 CVWsDy7unAsRwRp9TCbwrVCjUnmHsVsfBgoXeHcze18as5VIOkEGlpsOMrOLbNRn FWpYpEqMw4xJ6OupvF6L/sKxRfmrCj/Up7S41stpqWfCL+FDT6T8rh33ns9jS5Ed 6XWjXYqV8mG1jWNCnGSKmibiEXWEQHQaczZ85VBoJX8kB1FrRuaWagv3yWNQOzg= =ztr5 -----END PGP SIGNATURE-----