-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

To ensure the image has not been corrupted in transmit or tampered with,
perform the following two steps to cryptographically verify image integrity:

1. Verify the authenticity of this file by checking that it is signed with our
   GPG release key:

    $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import
    $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org
      pub   rsa4096 2020-02-05 [SC] [expires: 2040-01-31]
            A8B2 EF42 8781 9B03 D351  6CCA 7623 1C20 425E 9772
      uid           [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) <release-buster-images@turnkeylinux.org>
      sub   rsa4096 2020-02-05 [S] [expires: 2040-01-31]
      
    $ gpg --verify debian-10-turnkey-tracks_16.0-1_amd64.tar.gz.hash
      gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772
      gpg: Good signature from "0"

2. Recalculate the image hash and make sure it matches your choice of hash below.

    $ sha256sum debian-10-turnkey-tracks_16.0-1_amd64.tar.gz
      d04950db59ac4b1abd808f0084b9d79ce18675a333841e09105bb7d73b8853b4  debian-10-turnkey-tracks_16.0-1_amd64.tar.gz

    $ sha512sum debian-10-turnkey-tracks_16.0-1_amd64.tar.gz
      3eb1d68363b4d111d000cbfa7a7d0647cfce588e1f1bed38503c9ed1c4092407cf5f75140faaa0d6dd9994f1ee9a750889a19e630b9faa4c5f718a1c21bd6bdf  debian-10-turnkey-tracks_16.0-1_amd64.tar.gz

   Note, you can compare hashes automatically::

    $ sha256sum -c debian-10-turnkey-tracks_16.0-1_amd64.tar.gz.hash
      debian-10-turnkey-tracks_16.0-1_amd64.tar.gz: OK

    $ sha512sum -c debian-10-turnkey-tracks_16.0-1_amd64.tar.gz.hash
      debian-10-turnkey-tracks_16.0-1_amd64.tar.gz: OK

    Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted.

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAl8Bl5YACgkQrF6wBJPl
vBzjkQ//QkmLJdoyROeyXxep+uDABYBYGZqDQpQ+9AINNN5qe+iT8HkdBJ6SacHP
9QTZuSq9WTZ7uOQP/36l6lHmI0bXiWeNw90zTwKMLoR30IG3NqKJPAWWYsCS931r
IDPkGFi1Tz6ZxFjeSd+BV2yEAGZINJJb0e7ilk66ptcL3LhVhC3wJ13bvK98Bk68
79RT1thFsJY4IK/F7YHYPhwa8lxK39dwQ3Zo77N9yJzzTUzIKCittBVsHZ8VCayY
Ak9kDsIBIUkVq1sG/zdkV0OuHzSRNA4Icsn3OnULWk8b3LaIFwV3weTWWF7IJegr
UTTguoL/SM/UPDyfAQGbTwb4YVZTm7wtwxntPwfc9AREeinDm7RlG3XmLcqBG4U3
+1SxcHDE3Z1XKzpWWci6lTxnW1LYW/sRoCukxEWJbk+HWCzEJgaF3HsyR+aoATl2
pj5KIU+YNhyRCbbAPZhiU/samJ7vGcG1xtOVOVxZPemDe3fMEVi95XBVMZrOHrss
yVPmEzIijVRFvIANL2SDTn55Lj+Uon368SKXTatiCkfFnU+NugPnGdzlcx4lg+FO
UPIR4iMamFPtRpLowtLLlwnrQA2CRsCoteCKb7wfRXFbZecupdDmsvNbG2VMnvpQ
Cxxunh7HMs76khY5WBKLb2fhaSnc6Kwck51FMPG5MxSamCQ20GM=
=G7QD
-----END PGP SIGNATURE-----