-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mediawiki-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mediawiki-14.0-jessie-amd64.ova a0b08879cc1956c92fd2d5c47e749930 $ sha1sum turnkey-mediawiki-14.0-jessie-amd64.ova 1ae7e46c78cbecc629296956122306bd1f9d53de -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNYiQIAKF7Mpy0udbz5QHR77ufY0y5 50GZPAObZxC4iJ3VFqpWHLrvmMc1uoChT/sCiyBotdcnQyIwvH9o7r3ZzwwIZn6d BEdB6OmdPHYOewi0rzrFQDT5PgG3plHr4CccXacpsgyTxgR4IIeAkyUxIqxkRhgt Z8aDCZN3WWXAhzAYpF5imdrxOMH3aRkaM6vuG+QBxeBAqj17eJk/2vy/RG18FPUH SAHLfInsJ0IzHZPn8r9S6e611A6/lYIzsJsI4gSQZsU2IZ2CJMFc3Ia51sjzvZuI MdKPtKMB2GZhTnh0f9p1rPuSX54vHaUpmyOkCCRFxK0exf+K3CMqDWDmY6qL+q8= =xrd6 -----END PGP SIGNATURE-----