-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-apache-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-tomcat-apache-14.0-jessie-amd64-vmdk.zip aeb902a6fc1f88f317b3ee75942482b0 $ sha1sum turnkey-tomcat-apache-14.0-jessie-amd64-vmdk.zip 6baa206305cd0bf3c2fbb24fa0670a1a9156ad23 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdaAAoJEIXCXpWhbrlNUvEH/3/F+zIu8n7acxZ35LDrq02M 9vQLVGuMNt+NcWxR45sO2qqJo6K/o4fdyo8BSu3xUZYMcyV7V/Pi1P3DH5GLCaEl bPb929G1yCTTPUSPfh7c7y1h3p6aRGlDhjD2NNqAmCRcX35bWzYoikmnFKq1voE4 PLOiqZZapfKSUrNA1HK+536KckU8PDZzBqX90c3b3Q5+zIBjSi5bBAZoukeyYUep MHmfafLibMdk6mcfuNvWpAPUev0k6KV4BL9n8ird0i4VV2qPub83yA3D0Xdf0O0h Tc5Eejnx18cXa6G8i4JGNsd4bb1o9tGrB1X98ZlpGddLWQv3qh8basF7JHpzpVQ= =9ju7 -----END PGP SIGNATURE-----