-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-plone_14.0-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-plone_14.0-1_amd64.ova a0c1682b9578fc53fb21725021c66cf0 $ sha1sum debian-8-turnkey-plone_14.0-1_amd64.ova 8af72ccbddabcf92cf991b1ff4234743c5309e90 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWObxVAAoJEIXCXpWhbrlNtvoIAJOJVk8j6H648N6HxaO+Hn2n bBPZmhEOCb9tF5CnpBVISDxfMXkBKD5K55FJqvFZwpi3/pLKvZ3o0rkOcHYwC7gN AHkqf8cQ/+0J3wmRmaAZG+0MX3MsS1vOX3mEPcLbaDsTq0cel4GM0rKrJZTEGPLr Hrw81sINfR7WCrdlYKDIU8Lk//kFwqpupL/wqApE3zgjwyJzplKH042y+Gxh5xXN wJECofPAMe22gHg2US0vFI97BeMXjfuW1zJeHFNgRMMMllz+IC7rWDjz8YmKuyCp LGco5ji/bq/il8aV1Dth5LUG45c1+y2EcbwEuwVy3TjJ2aPQW8ufr4fwzwFb+0M= =mbp4 -----END PGP SIGNATURE-----