-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal7-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-drupal7-14.0-jessie-amd64.iso 6dc1e16cdb9b6bf48c6b5840c0193666 $ sha1sum turnkey-drupal7-14.0-jessie-amd64.iso e65ec77f0a0b26772d7c88401be40044613c752f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BroAAoJEIXCXpWhbrlNrWcIANCX0vl1Aux5QXHnRSEP71tJ 6T5xFziMdI3vigK9uBwElmTJ+9bw92rHUoh3f66Us0k3CqPyZ+XnUYaS56G5uxeP T1rClTONVwEV8IR9cu6x7Gg474R/UQ6PPLEyJwTfp7krzh7O2YGiNB35RkKMp88V +b4YFBkn7BrlAynbYvOIlBTDLZA546NQf7kzJmMTwIZeu0Y5hD1hWnwQhwcTn3qX HuS/Q2wEqjiPA2EgtGLHI2tJGyBTxcpO6YjdWuTzAjog6FbGGMx8+AcFd2mwYhw2 cbe5OvgPpB0enQa6PWHl5bBR+0AyXH9NOquLN5fpBpt+B9qxUZh/S6ISRvAhICc= =lVZN -----END PGP SIGNATURE-----