Point to KEYS file and documentation on verifying release integrity.
diff --git a/_layouts/release.html b/_layouts/release.html
index ccaa220..1359d4c 100644
--- a/_layouts/release.html
+++ b/_layouts/release.html
@@ -37,6 +37,13 @@
 communicates with. The source code for each of these may be downloaded
 below.</p>
 
+<p>You <strong>must</strong> <a href="https://www.apache.org/info/verification.html">
+verify the integrity of any downloaded files</a> using the OpenPGP signatures
+we provide with each release. The signatures should be verified against the
+<a href="https://www.apache.org/dist/guacamole/KEYS">KEYS</a>
+file, which contains the OpenPGP keys of Apache Guacamole's Release Managers.
+Checksums of each released file are also provided.</p>
+
 <!-- Source archives -->
 <div class="release-downloads">
     {% include download-list.html