-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-processmaker-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-processmaker-14.0-jessie-amd64-vmdk.zip 736c88ce06c78ebbf73dedcc75fcc763 $ sha1sum turnkey-processmaker-14.0-jessie-amd64-vmdk.zip 18606060e60d42651a2411567b73a8f7f1c00deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNSNUIALgknxroLwxAoZQdOAwW2Rsn 4z9dOBxPzqCo7jlZRu569/H1NXlwyv8LSVoJLp24I5GXaQmdFccQmdzDuJEfH61K IJJia3qEQzPkrbsvM1QncLjvbh2Hr3c9wpjBUOljvGnFKJnSueyaauBNpUUsu/oE tFac4gLWiZnCQdjGR6JlVFnqEDnlGSEcwE629jAR/fC0mcaI0NE6ndjfEi4CNr0Z w3Dq1dTDaIWkihKYw1UKnJVdBDxGJkvMf5B7C1WUZJ4vlk25j+/c6Eid1LeRAjnc GIg+G8UypDzeRY5WllNpHexdLZ34TVVrgZkEW1oJi70MJK5sFb3myCQ5LvEG7LM= =ev5k -----END PGP SIGNATURE-----