-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phplist-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-phplist-14.0-jessie-amd64.ova a5c6c29acd2259e9c9f7aeaf51a449c0 $ sha1sum turnkey-phplist-14.0-jessie-amd64.ova e2c2adc66e0881d151596dee5fa18412979c5ea8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdYAAoJEIXCXpWhbrlNkyMH/1oP5XmAEv7luT6YDSsYiOWH ez2ehh8d4xJ83IKZmNns/yDjWDXKGM8K0KJb6CnnNxvxzn2DIntR8kU73hqpeze/ 6ajejwWeVCg/nS8I9noEdhwbiDCxH1CtTNRgNVJQEb+b4oAr2emiQDQhs3MDyigY dKxijmSqglKzihM5L4wqMmg2Oo91xbkBeYacHDgYI7agQYkggVtJe+fY3JnBpLow HIpCzekcni3f8HShSQSwqbvrW134OTIdmf0CcBio1sGWsamejfXjb+SFEwIBwdrn BMCqcJnMFqodZ/zy5203jA77/mlSF+Gp8YocdjDjhRifwOIqAlEC1BYcf9bRA8k= =z4xs -----END PGP SIGNATURE-----