-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-concrete5-14.0-jessie-amd64-vmdk.zip 21d6c780ad8493e7d42c924b781e5411 $ sha1sum turnkey-concrete5-14.0-jessie-amd64-vmdk.zip cce027aa43cbdcaffb83b99feabdbbde791e5c97 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWXYG9AAoJEIXCXpWhbrlN+1cH/iMx6YNiT+zUHtAX0L8n7WCl oQsBPKu6WXdum0rLNhKfpGkiyj4T3eGVhVeHHCXHocljYa+Qx4C3B2oqVFV9ct0w Di/M1nDIfCiQ+erqoOy8pFeDmE7rXvWvhpFay8Aj1X3HBoYlwCqaq8QLZanSslgB 9956byZZuaGzNqa4i/24inyIQv8Qa5avzDZnDdUMiD8X6ij7tU5gWLsFaicfibcK QmVktJpZO7GIGzJBAdd5nYLUBhm7XnbiJIE5Up3C9tvgE3SXj1vSHOobkX8fZh1J BTWs/FpTxFmdx8iJVn/j2MKA+4yH99ot35rs5/y7kjwZns7/+CtLmrEd8UUFoFs= =+nn2 -----END PGP SIGNATURE-----