-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gnusocial-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-gnusocial-14.1-jessie-amd64-vmdk.zip 54a3670d46e81cbf3a4b3b850b1b204a $ sha1sum turnkey-gnusocial-14.1-jessie-amd64-vmdk.zip 7c27914cd1afe80fcf3fec7246f731632eebf7bc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnzAAoJEIXCXpWhbrlNMnMIAILL2I3Tc8mSrEkWoRGlgmkB zD4gejjKbHmOrTI3RmAK3b94J8MYLpSdX3p3v7KdkhFF5Z5hckcrubeCf1qPZyb4 8d/DG4j7VVaokMa9S9+AyLOxs+FOL/qcO+Cljox23hqtUj+V8xsLVz41f+uLAVUn 9iLX+Ol1vI0VwkxRCUaLOtwt7W9JJjER7RY1Ot0Ur9ACdO3m83kdxFIuQvTfDlqx +lKvfobh3S+PJ1lzyora3EYB3i3BwPVxM2RxZXh7QRPCp1JlBKpdaJ7C8ymiJ2pl mesOWjtVgcmucbZzu4+J4KdoHPl26EK8/gVY6EJnlOTZcljEAlYbHNL5x405QRM= =Gcpa -----END PGP SIGNATURE-----