-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-symfony-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-symfony-14.1-jessie-i386.iso 454911fdcd275741b6c6f3dfcd4aa97f $ sha1sum turnkey-symfony-14.1-jessie-i386.iso 49b9eb7d0ef63278a2429d9291b370080ef3f1d5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNpZoH+wRjgTftylU/1ee4Q6Bq7eqr I6fN9YtXvEUZVeDPw1BfTXGhX+uSyh5pGxLavQYBUd4TvVkRF++BuTO+qf31RYJN aiFoFjS7TZgAaasa+rK0MMb9E3p9uZ0bpyq8MZDrOIXdGYp5mDqu3MFiPRVaKXL6 nfc2SEoUD6bFkft5S0TR3obeijZA5IS9rrN9lnt/98DJa3tNJ20Bv3tRHxOgc933 u/fTe/lLU4MVM/7kFO+r83CTu3EMutLxMPrsY7ir4YdJ4Ma0Cg5GhYwSaoBU46j1 3mJyAcnMvCiZ6ocI4jKYkNWfl1gcC2MFnN1xd4WF8KZi6xEpp+OXDfqTqGYBS5Q= =pi/o -----END PGP SIGNATURE-----