-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mibew-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mibew-14.0-jessie-amd64.ova e5d0e7bfed5b750cb09cc0e589028ecc $ sha1sum turnkey-mibew-14.0-jessie-amd64.ova 5572ce04f8ffa873e678e16a0c48d7a4e4ad4ae4 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdXAAoJEIXCXpWhbrlNhHAH/Rm6HaJY/fT9YU97Ay0y0mFz Wor6WxaWSAVjF132OzmpN9Q4ZwVWXIdfbXh2HFTz6rr7r5baAlkTAGljosz5LS+g 1wTBuKEJExy12tGaCSJmNDvpxhN7LCP4tfpyte+DZGZAqyjr0mDehblAgVazoUod E2NpYqmmlYZaaTT57FPXLgzlrUqdoD85+Q+Q0+UgKHkYdUBoI8zC6NWDHdjtQEQ4 Hi7ddzr62KWedEPOKIN3FxV3AGkttc7H+icDOdJe1hPGhUGADsJLOAYO4CFxkB5y aC33ynFIi1q5wZLMbw+23AEYeJVwsygL8NUcRd4OvXHQBuKpn7IntFU86ejdj24= =3Kn9 -----END PGP SIGNATURE-----