-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mattermost-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mattermost-14.1-jessie-amd64.ova 3b23a052dae7aec4b97bc227367f9c61 $ sha1sum turnkey-mattermost-14.1-jessie-amd64.ova 7d2f61eeb207ff1f18289703ab6618dc5771177a -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXRb5nAAoJEIXCXpWhbrlNFhgIAKe+JsqyOjcIxyk2CQYtUyI1 jtre7jRNNzO2CXc2A3fOAUMO5iFq14L2HCTwqaEOahabX+1r6D23q0g175lRWHQM MediAVh58y9xTZCERabiP2+XeJbFa+ptowNuysXmvsJ5ficanm8OTJP+H9GFe4q9 0G4vAdyEC1WQF7kufuwipd6CIyakg63HLboTlbh4v4p+ycrhImUYWWOy6lM4LnV1 401qaQj74ZLc+liwz8TjTvY/u/jsE3UfHaLlL87NszN0Qw7lh4IrSn7p1lZExH1p GAkxmjLI7B3s+cmHsa8dOzU/sbzqm1dxAILk4vuh2ZvKopVPjBCxYd2vlqNaKO4= =QAf3 -----END PGP SIGNATURE-----