-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-projectpier-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-projectpier-14.1-jessie-amd64.iso b1d8a809f89ebd7bf69acdc81fad1950 $ sha1sum turnkey-projectpier-14.1-jessie-amd64.iso 448dc85a86e830223e234166447837441a1b6b79 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNIHkH/1qyjfZ1gxnegB4cZstWbpN5 iur//esHQVBg1YfYKmYVzYS7pVmJ+6uWjciHqKByZyeEE45BY255e8dKtZ6MUmYF shAnq0tBhvjpc2LmD2Cuj1YGwXneCmJJvbYEiBpdzH3UxWtP9xbNpJgV1K3cV1Mu L8CADIvcfdBCVXCDOx52QKjc9A1zzv27+KGRBaAm3Tx65YMcd7G9r/AWmaOE8NZb EtTkXiqQRCza3H6ABmsuuNxhtPcGgPOEEH0ZLMuq2k8WR1I2WKTqNgxxGb3FpHoO g+uJ4CZDEkEtrYvcxN4LYGnAejfWuF2zBr8xRU0/GuYtgWsq5UqzU5HnfBZXUww= =v3kX -----END PGP SIGNATURE-----