-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sitracker-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sitracker-14.0-jessie-amd64.iso 437bc5dfd1d28d4b11da3860de417e68 $ sha1sum turnkey-sitracker-14.0-jessie-amd64.iso a1cb66ca02c4c9eba02cc49da2c601aa9be66eb7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrqAAoJEIXCXpWhbrlNbfsIANlX8PCjw/Ww4wQ/WmpKHi4a Zx0qDnlvLGwH5YHCXilRxVcTrp4YXfcT8sOilvqaABUupIIcWeVb8Ygt1u0etTZr vh+inYKhwqqaY11WlvDhDM2Pk/3R6mZYG3y/hNGwbi+1ClCkN/boZUPu9dtOT0lB im3AKn8RBm//6Jduw6WSr0PalPqSTgEMQM2DZxBxk3pSU3M2efaNBREoZTwjilgr a+d90S9xXQvT+ONHcHW+uMS7AtRHlWLh/N97qbtJtb+leRRJ3NuXkcVdidUXrF7Y 7JhIJLMzrNAFczZLJW6QU3omWjgtVbGqrcWpYeqJCQOzdDyoEpp7ZeDME1/vWvo= =apYL -----END PGP SIGNATURE-----