-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-concrete5-14.0-jessie-amd64.iso 48d2dde51712dcd908cf0218f383f080 $ sha1sum turnkey-concrete5-14.0-jessie-amd64.iso 1c7ff07136b87f09e377e5dd436fa2dc4d190a8d -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWXYG8AAoJEIXCXpWhbrlNd/gH/j3Y8zga0vjcNEk2532tWhJz VWtnTl9xr9IQrk4DT6E6TCoMI2JJZyeVBbKTF7vV4rIWlWZd1WfFTy747yM1zfe2 K7Ypy98TaGYGmET0GL8PhMbMAUmyh0m9e+I2favBc9UbU4KRym7U3iQvQh78nW1c xLc+IWMf3dwD2Z7srONYLwCf5dwSi5dZ2hVXJKPij+UYchoJpbNVwrGdj2wXpcMn GIiwqgCMxr+Gs47mnbXBMFnJph15OG/L0oX34TWX2BC0iT0kBTcC2eapqlpLrYpB aEYTmj1nwsh+0gcPwufUKA7gJ9vetl5VdqNNOV2R30VqhZFIP15Ep4fJ2ycr8UQ= =2czN -----END PGP SIGNATURE-----