-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-owncloud-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-owncloud-14.0-jessie-amd64-vmdk.zip 777e86ddd3bd6f387b9df574c805a656 $ sha1sum turnkey-owncloud-14.0-jessie-amd64-vmdk.zip 02b032e16ef9d2b012106b20acb6da4675cf5672 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdYAAoJEIXCXpWhbrlNYksH/13YS1tIiOhhS2Q/UVK8zmA5 MeFICAxF7PCcRDMZhjothc8A4aBxQbtdWzJSsB49leRld5rNEtdHT+uUawGPtjGE IHlW93mch9+11eUPXcpwecokHV765kZjzDzxZvboR/NdQgvLt8qe8iXKNI7URF5N eHWYiBIQBNq83I4Kyd875FwBk3g3tqBdC8Z6SzE0opP3LuAwU74xJ3dkIz8TCo2B kiFMupwVM7CbDCSu/J+eBxjca7o8bc7CwaM8Q0FFBMoyXCrvauTLxNCWKhdAck8C ljuFye1tCuP4S++UvnSwXF8GXo76oDjfUTYxmtrSw24HYqFT9/yiMHIhW1/yIpo= =vRuv -----END PGP SIGNATURE-----