-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ansible-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-ansible-14.0-jessie-amd64-vmdk.zip bb840f8c523d14a3f1d21a691c3fba6c $ sha1sum turnkey-ansible-14.0-jessie-amd64-vmdk.zip 213803db366f833591e95053de5a804b53d9c9c0 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdUAAoJEIXCXpWhbrlNOggH/izXYHJqcPqa9YKEfpdXN9UA gRBWkQ+p9fzm4GXh/gDawkjMGaeFC66I8TGu3luOd+1soefKBmq1t05ww3EzqpfW cc41Vo9p8lwVJ084iReDhL3cwHJPvZ1d4QbZHTqcEEkIl+JwfDw4ILqDEUkn98Dz M/l62XqwZAq2bol5F8aIZEVX+mhjobwBBTi976EgrirtupJr/RQEXvKdGQ1fU5Ed 49xxJMnw5QWmcv/QhebXq4lKoxDzKaoMZAeKSj0ib43my+5zfD6g7aAH7cYa1g9Q BxTt898kOWN/Tz5CFJ/89W+dXkgUN6N4z48fh23c4lHzZey2xE3fupKVzC3ZZog= =wXoQ -----END PGP SIGNATURE-----