-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-codeigniter-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-codeigniter-14.1-jessie-i386.iso acd3b572abc79ea3e5c3a609903825e7 $ sha1sum turnkey-codeigniter-14.1-jessie-i386.iso 2745315990530769e5aabf840a499761d207ff8b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNGcQH/RqwqbH0WZZ/6Wl1raZ4KvL5 4EpmbD0CHXVabp4xuQ/B/qWlacZiBOPxp1qEW/CJ2AbIoiKE7YhcaJSp+2sD2Gyw i0t4ukNPBNtYD1L2vj6Y8BovBJ21Cdq7pI2aPJQQCt8VluA0ZFWGg24mIW8xhQhC I8czmp8em1ufJwDyzt8pzmrv3T4db+hv3sdspj1g+iTRHs4bTwZ1wlP+dJ6Ihk6H OsUOlRyimWDpHnutyNxM1QVAxPsBymESHIThNutNJRYXNQymJxuw7YP3wam78EQW uCyFUh6zOr+d0FMJl/s3WihUvUSFZza8AmPAv5MuNZt8swUDNSEoD6lXIYp7Hsw= =Pkmc -----END PGP SIGNATURE-----