-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-moinmoin-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-moinmoin-14.0-jessie-amd64.ova 9b761c5bfb2080f5699380d455804ced $ sha1sum turnkey-moinmoin-14.0-jessie-amd64.ova 6cfb8f0aaf8006af2546523c86cbb7afa3d54b7f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNmn8H/RvG1yTZeX6m4cBxTzdF73wf z44IyDJ0VAxg7L26YRpBeDOEfWaFsi3fxJfEvk7IhsDXT/I8e5L+fqJXsaSL6LGz dZYdkscBmJIUx6m6IsSJvrDerFxInhBtdeWUIshStbwnMW1nnXN2UjshLixuZwJ3 xFIb8vKTT67l5x0BZ7ZYYoBPkxULuXs6e6aP2z/WDWBOpyQP8BUpvJqcgAwbL7yr qIUD2SC/Sz8QBSaZpWk+l62/ggHHvkJ6COwZlzQfjCeL48KYPwBAMN2edP0PsAWn 6pCX+TsKkv58Bm7NTeG49TliMhOd244RuY/rhhOePgC68d4IEyMJ95lghZgK5u8= =EEBR -----END PGP SIGNATURE-----