-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-moodle-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-moodle-14.1-jessie-amd64.ova cebd2a325ce6cd794474a855f0709fd2 $ sha1sum turnkey-moodle-14.1-jessie-amd64.ova 34482eda419566724d466b9f4a809f7b954791a7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn2AAoJEIXCXpWhbrlNZ08IAMUoCSok5Lv9yj7k3gT5/iJs WM5rRg4zFZ98C9ZIgm18XE2lrBKznzrLz8bbWe0p9RjR2y+0DLXd4xj2X9k0fhWZ F9oNZ/GgmrDDVIggfp7HIXXOR54CZNm98wJPB3HXUGa9jmLBv+ombmjE4quge1ea Y/L8Z0+/OAIcOqu8LaVMQAZdX7GqaACo7l2s0a3DrtxwWWKDqiBnUFEqPCWhrRIb MUfwlWMWu+7dQE0A5psWINOhNKTvaXwntJHFtoiw7xmzeiqZlP74NWvlkrM1EoFt WhUeCIq20jj6/+358IeT34lL2YfofI0FuBeoUO5oJidgk652gHa4RK404tcs5aM= =5vzA -----END PGP SIGNATURE-----