-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-lapp_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-lapp_14.1-1_amd64.ova 349d003bc57338e0094287944b4f22f9 $ sha1sum debian-8-turnkey-lapp_14.1-1_amd64.ova 62ac0349afd5864c858e44437b2effb579979945 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnrAAoJEIXCXpWhbrlNDWoIAL0bT6kVgcgZGU7z50/h1/Kb BUQVZMn4JflQA4WmdqshpKAo4rXCz4aCsWkKAc5gRAkn6U4GSvzh2D30m01f5rhU oIQwdBM323DTi89OagFwzZJ3qa4iHYybTd1v/4rYA+p9ORDtjNANMXObpEvoool0 S1eydWXCudETZzLIEvuKfy3I5tjrHTxv0pFul8Y0NP3yFpz3ta/b4Af4I1y+Iqbi lKqe5M7ZO7tq5wHEzaWgHWxxhFREan+EL7H2hneudKr5qwm4OyNlVAkd9MklYzOQ CzwZmcnaPmDxWYajEhSQ1UUPQtR3T8EbiIBsNwLTBYUXRY7LLh5vyMmOupe99K4= =oruI -----END PGP SIGNATURE-----