-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-dokuwiki-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-dokuwiki-14.0-jessie-amd64-vmdk.zip 445ff088192365dc91c2756ca7790c66 $ sha1sum turnkey-dokuwiki-14.0-jessie-amd64-vmdk.zip f125af6ecc09314ff0b5a5ba38c2c095c3c291a1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdVAAoJEIXCXpWhbrlNPlUIAMeJpBURJJU7PI8XIqkCOtKI r7NneAnUNXQeaMSEccViI3DdTOP1POFGVh26oO2sKmDbNl/uiN2M6AY1nslngCuD v0/gleF3vnxhoEhNdTiCT+hXD2C8zEDDhbKeaBttaTZMKcb0+wxjQLGP6XagGSgg u5ZNdjoPm+dnIHWz8DcjTVhJQ5V8rspPexoUPWAM8NAGtoGzk9NjP7Whr7O3I8Wz DFuU5f92pm+b9OanOZ6o7ps4uOicoBRMsepj524Hlyw4ovwVItE2dzaIpJaARquG brdiXgR1rgdUEqk22UB70zWfWHXYrRqM+A6yyvmxPwY7pcbwN6KSNNdlnbsx5yY= =eyF3 -----END PGP SIGNATURE-----