You verify the sha1sum of the iso then you verify the sha1sum is the authentic by running this commands
cat SHA1SUM
sha1sum ( the name of the iso ) verify that the hash is the same
then run - gpg...