-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gallery-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-gallery-14.1-jessie-amd64.ova 758aa7de0d9f72d5f9e59248ad8a8a1d $ sha1sum turnkey-gallery-14.1-jessie-amd64.ova cd0f06042d7de73a40731e1ea4355faf1a908c29 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnzAAoJEIXCXpWhbrlN8tQIANJR6sl5ru8WOVfHwZJO2sy2 UGJQkoQqRhMMCLu5J8Ak1qIYl/MbDp+Mcoze3U2iGPCJHafhp+2+VngiL+FcjEx7 Hd9nHNtgnun5wsl43obCGBVJwKoQhCIBSyACOhEjJagG/hXOLIp0a3kOjR4wUtMX 2VdjV9Gqer03eAK1aNw2TFE9aPLFwqLdClKGG/dS9FJue3D/LCOXO5LP/Sw13YXk BmuE0kcDcPhDuAHBqtxd8b+CxXR7KFiS0unVBTW079n+w+mS8jG+OqHW40jI8F3D wnyIUFw0Ws4Uqm3SfdHFHaVJJpbo0h/kz7ALQ3gqGDlNrJs6nuBPGx/AU6sSFGI= =Hq3s -----END PGP SIGNATURE-----