-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mantis-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mantis-14.0-jessie-amd64.iso 545ce1b87ea16a0be583daf22b26a6d5 $ sha1sum turnkey-mantis-14.0-jessie-amd64.iso 282429c9b7835a92e060b67e0bb7e9ccee8c59f6 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrpAAoJEIXCXpWhbrlNu7AIALrD7I4r9P1SBe5fsuNrEnb6 6ypFvUSVViY0xyp0N7r8THaiVVQuBkbs1m9GBbWNtFc+NL3RWqICy2vgOmBxG3xN D+h/d/gUSs13NGIgIDxnn7jWhd37RN9dUzpp2EMA0H7m6LyqT1ismbchUpcVqJN7 dhq1yxWn0R/jnKP2pwK4yzSkAtpWH/BBJ5Zq9wkHyIbrz1BIY1gnLvPiQE6Wg180 HUI6pKtsmP5ZSOM7Fe4Pwo6PNjXp3IuE0zfaQF8kIE9pf8L8sQxr7gAxGqcDIMsO WUsz0l5ketTZ5aSh2g6gyt+qr4Qbm5svdVD/coGLoqirx6HF6pxLa3PJRU53E1I= =uQHC -----END PGP SIGNATURE-----