-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-tomcat_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-tomcat_14.1-1_amd64.ova 722349c1122a20229af20e0828c6bc43 $ sha1sum debian-8-turnkey-tomcat_14.1-1_amd64.ova 1db383598c454d4e7ef7721284cf64f9b8fae1ba -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnvAAoJEIXCXpWhbrlNOOkIAOnGrJEYv6J/MvtHw3PYyMas IEiGpWcGB6qyumzYpgaQPoVwuirBt3DEFSx0OLD69IPXnKJwRWHxFWUmqAl/kCjF fumVrVrByk6qULYPY5ubQRCTd2xD0ZSSakYAGedZ1XlDj4M39gU3APOnjr8XAus3 L0qGxQYg/wUVTL40sxsVdq7Iuu974HepZraiPyLenb2YZyot9Dy1JUkFWlvrvrm7 vXpFh8DxiNcqFx8w94q/XA8G11Q6E3GnRqB18Q9cSG1vrZkPPg5GI8KEbG2LZXqn urvJUaTY0IHAy2mNhIO2Pr+QPpfqR1IqmJORx4t0H6RbeAOqGDYRgIWKmH/vvHo= =gUQy -----END PGP SIGNATURE-----