-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-orangehrm-14.1-jessie-amd64-vmdk.zip 8717431d60ed2256b34c01d8b266aafa $ sha1sum turnkey-orangehrm-14.1-jessie-amd64-vmdk.zip f92da68074a7331e4193b410acbf0e3b6913ca20 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn3AAoJEIXCXpWhbrlNTW8H/jbvobRB5LtjEayeGTe9hDw3 vP4qnfkv6tVtg+8+rlJXdc9bkfOSb004SL0OuVSjMV178GATM7KFUhbaMn8jsv7E WH7jdjIwhuZd3bED4Cf+8GviqnjX/A6fvB/FQ1l0i5L25AahdxgmNlfO9KlLUiXG 5vvDAcU5Es5l3zflVqXINAgAVeHi0wGpJ1A2W1POf4Fvzswj7GDTZxSDz5dddE1f wL85ksqhZBhVvdrc85u1VhJlh7VqjRK58+Mqt/QPcMGhiChxkd1h1wgjjuyeQ81i 4ChEj6a7omqDejzdcyZdo58poB8efdSD1yDubTzZ2lVlE0Nkdj+abnOcSKEJKy0= =79d9 -----END PGP SIGNATURE-----