-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-drupal8_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-drupal8_14.1-1_amd64.ova 95c8f000f9a95bce93d980485fe8e6ac $ sha1sum debian-8-turnkey-drupal8_14.1-1_amd64.ova 6dda5397dda14d39f92820d4b6bc7bb6a842c0eb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnqAAoJEIXCXpWhbrlNeEQH/jLBFanc2ZfDHa3gQy4aSrVW tNY1iI3Q8nkiRKwTzWzy/bRP+ID4vVdh91AzCFd3Rdp++nyadcNCa0PhHRtXVWes dH6J29mEYKCRwsfKA1Nz2cn9p+FCaM+nFp/BB6m+f8N4ZviKWp+KMUapWoQNsCmD r9yd5qNx3PzG4nTKENmpDWylI5/AQNLbXAzF3Yy/FKoT19sHt+Ep5GKtuAYPQolh teKD7EbYgwjQMOxAL4/YUJYrTPYmMW6kJP4NvDMhI3FCJH6q5ATnqqyo5vJs35Wd Fxj1nQaZFYQAZTXesMYJTGJyiLC9pJjVh0qUMAL+TJbQvvYQGA0Vmo8CWYncleU= =yxjk -----END PGP SIGNATURE-----