-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-magento-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-magento-14.0-jessie-amd64.ova 33af5706ef4a7a0cff035a9e65462221 $ sha1sum turnkey-magento-14.0-jessie-amd64.ova b0ef262ab21d70fb8ddd09c17dacfc480ae6117d -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNXCQH/12RbtT6Vjl6QTqlTeXrLix+ DkpB3PSr3rcOl/azGvf9r+t38Eq5mRGHGv3sJzUElzr3XKQFLlROzSzFUvgJU1fz AHMuYdvFP3mqROy33PKB2yilgHgn2l78E6YtJgbci1lj+r2idO7iUmH+CBrLGS57 zVgSvpG6G0evaM8b25yQwLlenPZxjM4s2apUi3LcEK++eVE3kCfsvELWNOqQSm47 GJMgVjAm7Od9xG8DE9/B7x87Zmv0fhrxkE6uyLMJRa4ikuEDIUgA7JrFiJe1w2Ob OppVRNtf4FU3mtR8Zgn8bZn0O3AHRoVy43tHMn/KcgXRd9NuP5H2SSB/kT4UNN4= =CLCJ -----END PGP SIGNATURE-----