-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tracks-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tracks-14.1-jessie-amd64-vmdk.zip 49cfb0d2d0fb3735816b93face353144 $ sha1sum turnkey-tracks-14.1-jessie-amd64-vmdk.zip 3b81bd9aed99b76a3decf1e17dc17422c2de163a -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn7AAoJEIXCXpWhbrlN730H/2wg+MPXKl6irHRWocljMI5x 2n0WDZSFv71MLydhZS3US3FiWL2+Z8WV/DlLioZrdPueYrW+W6mz9xw91mMQp6R1 5FWiyXYb5GnpUmrxzu6vh7bnbAtvd/yylM04x0efzSm41907uwrlHa+ptnUra/xR gkjylg9W2Hgdq2iVSPT8Q2u6DP4Mvdq2ovYsIJqmK1AfRqWufWyuVj9Oarfxhp6a UM9uZpMjWMgkmGZuzFaNFLjWRS8feyIWoGQ5ObKl9dBfk4v/Fbw6nV1A0gFys2pr RpJ//YHMbtrjQH1PcDkghw0/SlRoin7dKDgXkt/+oPZgXP9z/K6l8/NfQeLvfe8= =XOTv -----END PGP SIGNATURE-----