-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-punbb-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-punbb-14.0-jessie-amd64.ova 4e3d50b7ef9b6266291df3815b03c804 $ sha1sum turnkey-punbb-14.0-jessie-amd64.ova caedb50971beda94b17577fa25f86508abbae1b9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNm4kH/jKg9jZ9X58pwnC8NnsS3tos oiteSw04AyHF6kKoZWpaOGV1/Tw73NeAxy4YJTCUJaywdd2iL5w7MUj/TzxmTtM6 lqLHFq1ZihZwYUnHjOOjpOma8uaablfOTXCG9OUqJ4GPs6kbxZtFNa5z16ljpwWB uvUYbB5om9B6QmsI0ZhQ7y96nLN3bWjdXtIst3kxydw0TR9J/nWugMoe+1NaAQO8 tsjI33M6UNchO4QaZ7+0VASqt5pQC+f5IVD/TcRNoDx7IpPxV0mFSqizkq5+bhys i5CMoqMgi3MrX3HUUvwfnFqwruHTx4C6g9KzXSytBlWqUVt2Tt4GHAxcQAEfobc= =QdDf -----END PGP SIGNATURE-----