-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tomcat-14.1-jessie-amd64-vmdk.zip 0052ec39460354d1b4c723b5543178fe $ sha1sum turnkey-tomcat-14.1-jessie-amd64-vmdk.zip e9e7b1e10279cd823d075198edfcc5c298c10394 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn7AAoJEIXCXpWhbrlNLssH/RrcQfKypUh0Ox5GxeGbljto 5sbgVnjzVUZAzoO+WtrOrpZQU3lbdFjCf3BKeHL2dR/EcpcyyoMEQYyZ9BHGB2mu yZ/mMd2dqCwalrMCvlvgxP09sFghNjES4GwRu3mAcVxOjUMll2dQoROPu/cwLlOg 1uv9j6AAfAKq0DgY/l1qg7rEZeljlsv1ypRxM8v3ev4+9c9nJmQ6dR5FKSuKZfGI 97wz0yl+ixViBFI8GI6IuW5CcClG1sg3sG5KhCc9RamX22eiMtKCf8rkGxttMa9D HXQCUYVaz02mpDMaFkEubD7l+FDWwIBDYIg1FMeoL02nn9IoVfkwEPkHxEMhhTE= =1CXo -----END PGP SIGNATURE-----