-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-processmaker-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-processmaker-14.1-jessie-amd64.ova 4248f4606c6d4fc45535a344b201e7cd $ sha1sum turnkey-processmaker-14.1-jessie-amd64.ova fce665dabca1345bdbab49c2a895a8f01e378a95 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn4AAoJEIXCXpWhbrlN/QwH/01shfK4ZIJ7eHiGz40lYMbo VYmW/zPYkPsW0edidRbG0YXwONpRtf8S1s9p40b+Rz+VD8iNaiA5wGxQvoLd/L9L pl3HrR4hciHo7oDvM93iUcm0Dcxnyvj4UaS0pOzAM5jgmYYbE4NVnLWU5hkqRQ2q WnnUfdTcv+pV4iZSg3/I5k0FkXHI5FhJFXmolwFDSKz47rpv7VHTHbsOgPHDIOvZ iXkHocXXASlmVXV7kqzOaMieNGj6rXjGSt4vts839SSIE/ylru0VJKb/1e14SuGu cwCShOug5POpdQ4DxGg/pXS7Q1rCPSdIVRJ6iuDhopySJLm11Zu3L4fc7N2S8kc= =bS2l -----END PGP SIGNATURE-----