-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ushahidi-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-ushahidi-14.0-jessie-amd64-vmdk.zip 16cfb1adb9558263a69bcae22f7e06f8 $ sha1sum turnkey-ushahidi-14.0-jessie-amd64-vmdk.zip eeceb5abfd7bf115b01ae3fed42f8432cb4fe9e8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdaAAoJEIXCXpWhbrlNWMcH/2jiPm7vvr5eQ4rewoJ+u5YT XSRnMvkwSUnI9XtoNxlJr4FKPi9I2N1HlTvyGzEEZ3+2ApKqHQiQNcevgpdN4Tej e237wN3Yo57s42hp50c1XdF9yAtpjLS9lPJCvXzWD1wBa5UalXJ+/Aji3bNSJHmp FDA/Sc4HDAmnvp5VBuCCZQGcRoMhAYbdj8HANHXheQ8aYRntz/QRxV3MK+ON7Rao ImxZYTbvVpcjFAqZCGyj3tRHvqClItsjM5nvhkhRZMsbxncDj0UnoNFpGKfGsthO Yn5dbI5JaH7ids2ayKseBv2c7msr0RF8YctfmRjf/wMmKt3SL+GWDaIxRUZsiVs= =SBVp -----END PGP SIGNATURE-----