-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sugarcrm-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sugarcrm-14.1-jessie-amd64.ova e19a3011299cccbe58b2d2698b624507 $ sha1sum turnkey-sugarcrm-14.1-jessie-amd64.ova 2d1ebaf1df1f654fc0317c3b943c15fcdf904776 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn6AAoJEIXCXpWhbrlN0aEIAKlROf5PGZLxKO98x2heClTu LEGSs1NutOcDcq1G8k6TUfTKT1dzGXZojUEKNx+STLyzrCl1wduo8G6ijQB1xM96 Djr+ijCptLsENvH47VFHm8H9DkjF7jHyzsB/EV+AmWZhL58gjWe8HlTsTmS0MgBv yBg93OTK9v0PozTJOm0XdYsCKZ5pjUs4Ihy2StyA5t2W93uxwu7Cun+eIHq12TYn 4MsEhGVGt0VfkbFYWv3gmMlWEdrbOA1sjoebWtL/QdraLLA1TXXgs9x1V9T9qOVj 3QnuhVJPUZ1q4f0hTNZCdCuOpjRkFUUK2zBEr58phS/FxqQgwhNmIrjQljMIFJ0= =jC5f -----END PGP SIGNATURE-----