-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-moinmoin-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-moinmoin-14.0-jessie-amd64-vmdk.zip c8858b64b717262db6a1dcb5451d8f54 $ sha1sum turnkey-moinmoin-14.0-jessie-amd64-vmdk.zip 970d58fed089163d3513c2923f18656661ca0097 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNS3cH/Ruj62HAdmduZuScpciTacYe Un08t7yU74MPQZ/9uQapS6ml9pexqw4wK/3vVVl9BzMvxErKKsNPY2kwW2ZrA1qI hX3HBer+DO3nEDWU93ZyOzQRLSeWGRbG9Qy86RkCWkFGZ8SOAB0WkxItR7Bqjbxc kjaPMFcOmZbX1HLyaDYqreNKRpADKc0WDUk3O3L++0/py141rZw8vUG8GH69okiU spembndf+QWgPS58PaFme29sUvyvflIHK55Hb4R794Elv99caZ47lvx18p2wSshi RQZQpd+WcAnbCCXVtfVDQUba/+G1fnIcMG/VYWjaolebiD+ToWUVmIOpOZdUeVs= =bafD -----END PGP SIGNATURE-----