-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mambo-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mambo-14.1-jessie-amd64.ova 7b367ed0616a276ff9e90af7014cc782 $ sha1sum turnkey-mambo-14.1-jessie-amd64.ova 279189e41766c4fc340b391537eb40ed1578683b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn1AAoJEIXCXpWhbrlNkbEH/ioOWcj8eB0IG/MvWmi4rVss EqS42u90xflVAST4KClwb5a5jYT5LVHEFbeDzEshcOW+caYBZEsm0G2SKr68UfbJ Vle7nBmcdtCgO5r6qjdivohJBdHO+IYKBjvPbxUKeq8FXCqODtWtnK9pTgfTUyiv N/jbh0Wb23puqFkQZ/Kvvd7i1steEfk28SblRaGo6f2Hy/Y0/4lYWgh7dyPX2b56 HFj4nzSORfGEvtlHtHKfc2M0dam54LwIcoxpbL21G9izzGNbcEgBQZASskpcN7/b tCkArYLRaEvb//e2nAf2kajl1vQFO88qDivgURuymAFTkIABZjnps97tInaCN3U= =f5vk -----END PGP SIGNATURE-----