-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-suitecrm-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-suitecrm-14.1-jessie-i386.iso be8baf76c9536232ac9565b437120756 $ sha1sum turnkey-suitecrm-14.1-jessie-i386.iso 999bd19c778be92f5978c7486b5f867f678fda7e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNDwIH/1RkrcVjGVedzp2MnTVxxbde CfxllcXY1Yd6B+uxHBixhd2wKR5vebPOv278Cl/ktfq7RMQBxa1QO1iOqeZGlQbB vvo9UPOrnmlm6JJCZgKzeNngBxjKRTCy7UJF29pYC0iZrICx/dbYlTShDYYNr0m3 Nn0INkVrQhOjijm2a2Zal8JvCaGCr5Y56bdfSFD9PK8OKzVMe2O2kBE/8HVgFz5m QqQp1asKjhWoTCj3wb9eGG00vqF2K9k4gvcK20ugI+MH8U8FWp/xfze2l8FPIQjI 4Rjm5xJ53ws3DSkbtQgvCgk7MIfoCFB89V6kfWFy68WLLzZZQM2MRaBBLPFSnKU= =+TzM -----END PGP SIGNATURE-----