-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sahana-eden-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sahana-eden-14.0-jessie-amd64-vmdk.zip 84b9cfbe8e8356ac5559d2f1303dc53b $ sha1sum turnkey-sahana-eden-14.0-jessie-amd64-vmdk.zip ef1b74e9980f11ae6095de82b5cc0c46214c7607 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNNY8IALVcfrv/UZ1nuQ7g5BTKW3Wp YK7Exj+EP0cno2+RBVIq/Xhpqd46d/Apco5c2GydrgKpqdUl/c6BtisCgoDiw2eV qUgXWaL5N3gM4PwzvFDuDzE7a8Ql0//BtEyio2sEXrdR4dyHsQLaBCLxZHtg0m2u QCDklYqcBvA51CmQlbJ87EAuEdY3FA0sK7hjrjKH0KIDr4MTO0QISvZLVg6n/qtS PvS6IyAo5Tn2bR/V2DfqxpCapjZjOrAS1fK8ZnnrwPVoGYfWEQ9C6jemqKN5Doxx 3Fdtf8f+H7Ma4ws0uBQn7WzW6UXNVFaCS1HBytGHQ5570aaNJ9QS9beLo7Nlq6s= =Dj1C -----END PGP SIGNATURE-----