-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-etherpad-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-etherpad-14.1-jessie-amd64.ova 1a68cb073dd04639348e4e0d574eae82 $ sha1sum turnkey-etherpad-14.1-jessie-amd64.ova b7b0eeb5fd198351bc090ec0182e6d11d721ce2e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnyAAoJEIXCXpWhbrlNhokIAOg7/LpUIuil0L+HA+eo/0eQ DAhoVQof66y1bESM1Mwae3dL/Y9D9LHq0+p09DF4QJAGSTBORykd+4533vYTutHz Hnepo3vOW95o0TAV4n2ZVv3HxoZ42Z79UUnqUfAEHt9DOWUYsBtZXx2R8HKlfUKS DBC992ZMvN+cR0fF4/REvYggWKI2QuKVMSlovirScNLgvYDWgW3o3aDfF8eGNOeB 9hUjaKLn1CKLV2DSUi9BSNps3PvWoBNrTWeUhInlqVKJbOYQnHep3Mk5cztXUbaa jUgV/UlWKoUuHL3rfuRnxe4kRoIeFzuLcr31oigyk2ujrkle+fq1n/dlJJS04x0= =rD6J -----END PGP SIGNATURE-----