-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-lapp-14.0-jessie-amd64-vmdk.zip 35f70778287251c22c6bed195146025b $ sha1sum turnkey-lapp-14.0-jessie-amd64-vmdk.zip 39ffc3fb0a751f67f004e60fb84bdc1b759176de -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdWAAoJEIXCXpWhbrlN1yQH/3qovUs8bH9igVc/0eUSFKn8 6XDZupHXbLl0bTcIe16wBOJ6ABGvHWoOWhO8kWFQ8scbGcFowimZkJ69j59alAUL nFWBm4Klz2bJVEpeSmKo7C5gdAztNUY7PvlVzrFO7xAPlHx5J2FwsFKzWoD+XJwA nJEHZlGPOTOOLKvsm3B9jz0vzHOMCMFTBic+3GuQN51P71VR2E4GpbLzn0Tc/mzt CIOBXEhg6cz7jIhmRxX53S06715+63gmZPDmZEubEzczJUVT+eKggfzFeVjBNmAO fJKEzRR9kKkIypV+xc8TYcVwq+dTW75nn7Q4IlPYztJVXMu8lVkGBhaZDC0PkIY= =vZpt -----END PGP SIGNATURE-----