-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sahana-eden-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sahana-eden-14.0-jessie-amd64.ova e119fe686947868285401639037f5e48 $ sha1sum turnkey-sahana-eden-14.0-jessie-amd64.ova 938c0c4b5f0d83c3fcab7f7fac4b1966a2a861ea -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNHnAIAMHQ35YTuPzex9/g1R6YLRyF tT7FfZn1O7SKTquZUSx1+aiXgIG3GCKvJ/mZqHHWAFgDcHIO4SZF3DxLaW8HJkNN bIiA94j8Ftc7ghD1Ba0/XbQEuXnhsbQrZB6OHG4yVh/QoYHhX6QrIa2sxa/VsLzo +cAr01iqvJ8LvTtJTFlrfxmKCIoj7m6rWtCtH4U7nwBqwY+98SqdlWHrepFISoQm PV1WxjUwBsihZxhbAl5UcsaN7bTQm+EBIQ3wLuletRhv2iyIQ7n06PLrO33+AjZ9 bUb5gh2su8tPxfKzIyJHNO2LbIfCiCAVYV25p2tCQ08TGPPtD68uYDCiV/PsBW4= =R4X7 -----END PGP SIGNATURE-----