-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mahara-14.0-jessie-amd64-vmdk.zip 91b7c796121868fba0ae7d93e64d0b72 $ sha1sum turnkey-mahara-14.0-jessie-amd64-vmdk.zip 5394c9877c3c1bc904e61e9db07c6a665d08ddd8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNNvcH/iQAdKCt10f/ihXDq5dSBgSx l68ezepEekEaHnfXNI8YTRdwkg4DDgO+/6xrVIpbtw2xqdKxITCSMZtlC4IK88su 66qja34jY0J3saWrI9aNoHQFqU8jTedsbuWxYGJPi0ZZRCzFAwsiY3cKscv7gIhw NOcds5f2ZLjRs0Z7GfGt58kJwVTEDcUKkD5IdWQTw53hpJREQrYLh4REOV+ouKRF zcTwTAZAMjM5RlWREAQaCDZsjeu3hhSUjZbA0D6VLxkW2jN9tkJIHpu/OUhLXD3b nuzg6ZnF110wot/Bsyj/Wn6UZzVX58qgRNxbxvxsFGAO4QJq9vmO48OGPvAHakQ= =Kc5m -----END PGP SIGNATURE-----