-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-punbb-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-punbb-14.0-jessie-amd64-vmdk.zip d5fbb991a4a8386d6dd7409135d1da61 $ sha1sum turnkey-punbb-14.0-jessie-amd64-vmdk.zip 1a6f500e5a7539badaedb0dcf05678a176269149 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNyKMH/3fzcuDF/dKuyb+eBRf5leDa JB7tMKbdkK8zTBPfwRAmUV3HfgtY04n/gwYs1f7zZ4z8pCMR0awpXX1cXZJMmK4C LWmsrtBDhCcTzZrMEaHbTaFOJ/qfB4W9SIEVDhwbOiBODgNpLJSMoNA52V3hMbNO QQo14i6V6TTRby94gmv4nE/I5+DQd6CV1sgiOfRdTnQrpZ+V3wsnVrZZ05oHzRa3 ZfCyx6uR/18ukXAaQ80J/r6T+5dE3qpQU/OXmpD4lsk9rOMeTVp4cm+hHsOnr8O4 jBDF53KVJ3PbHY/yuFVRigHLJ9pG2j7KUOnJzfTDtILdtfyPT/APQvUEw4VG1m4= =tNfc -----END PGP SIGNATURE-----