-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-trac-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-trac-14.1-jessie-amd64.iso 9fb820d0358db3abd33493f32d7ea7fe $ sha1sum turnkey-trac-14.1-jessie-amd64.iso 74a54feb82e5a74d181ab4fdb421edfd1506cdf3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP1AAoJEIXCXpWhbrlNSFkIALYY1UfzxMrAKJZ6OjJuwXid 0eL4aGE3ZNQAOUi+HnsN4R1rfsfFB9mI7KauXv4rdJUxapeLu+Evcdx/01Q54tau tX0O9pS6fOhQ1PUimFZaWgOwI4B0cSTqb4TvBDn0jjEA+NjVgrUW8nLu+leMCnF5 RnSZ5UITquRYK6AaiAQkfY0pYWcplbaWPLc+20y6lI4ZgzW/0+w3DBFNzE8dvbIQ 1d6/uMPNWn+EnqvXdkqyb/WDHhL/6LDdWmI58qSgN89k9Sf3i4Nm8p7OjWPKANTj bHrXpdOEoGg+/d712oqIRUlcynEkXRFSSxaTdditx/+gUkHxNFSfOUUIbiaBiY8= =T5hf -----END PGP SIGNATURE-----