-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-apache-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tomcat-apache-14.1-jessie-i386.iso f06500ea99ee95cb9d577a8e54ec25da $ sha1sum turnkey-tomcat-apache-14.1-jessie-i386.iso 5843d39f7b80d1f19e43ab9c8baa72518a15590b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNliYIAOArvrH1z0ediszO77HdpkFJ wmxUHwCfWoofYdlzDCULEfXRb/w3SQSQHJGBcq6vkby56ygLPi8tAD/E4Unx3+39 G+AKkHKKGfXT1c+lWC4II/LzXGOhkbQKL4xBjOuw55RuuGKbBp35/cpCCBhCtuGm Foou0ZkVVZtQjM9zeVTnsNXECIBvS19rmz4rI9/LwcRc7kyIWvP4WTg4c4B62V7e UMP4plp/UfR5hKsSmefVGsxQ79Fai1WOEs4wnBY1QDjrYeOzTJbWcEYpTndEuEOR g3iW62+IihfuOvx6VsYYfiRa/rX8HiTrIAtnFNAwua6jaMrGk+WjfruRVogQKxY= =kcH3 -----END PGP SIGNATURE-----