-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-codeigniter-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-codeigniter-14.1-jessie-amd64.iso 9e706bfa62aa1558d73514f46e401dd9 $ sha1sum turnkey-codeigniter-14.1-jessie-amd64.iso e1fd83c2400e29338522e13c6e9c23aacd6927d9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNuLIH/2S4IKlKvB/dG5YWXVs6HAmH J++wxbevfAicpX59lb1beoeWB9rdytg9jjR4qv/3OMFN94JwsedyQmT7D8mSMlKe vlQvn3MT+AD15+BIaV+BV+ADt9CIhDJF+PeqQMxRAsbGpw53Je1dvAg3O4Na2B/r vLItkfeZ2ZNpvTldF9fBi7X9ZiBxJOXdjep6Btu5FRYWAaY5m0xgwIcoryAJ584i Y5EP5Bkpoqq/6kBBnqM2mUgq4tokG9+q0uKa0dYGCShQuVNko3A+qzw/zdjbXrOG 4G8UFbfH19kHOc6I6pe5V+fBOK3httZEM6hANK/tX2K+nahb7+8OWIPWlYbTd3Q= =384p -----END PGP SIGNATURE-----