-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sugarcrm-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sugarcrm-14.0-jessie-amd64.ova 34c942dbc3ed63c988f5b9b7e3e5961b $ sha1sum turnkey-sugarcrm-14.0-jessie-amd64.ova e085aaaeb82f9c38a1293b64aae9cac170f5c03a -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNMAgH/1Xxb0o1EZfvbg8psWdt6q4G W8c3OZSocQNGZGImMC6RVashFz0eoywJNNkZGY8DyUE0uy28FkoQ0bDJbO7KuzjK VuPgUWjBdpfgYsMnEymT2mSuHuEZfkbaJwQyTwzvDp29e3/hsQCPlnULG075T448 I46PexAD/P8YD8wovq/LNwJmPIUFkBPpBKAofwbYZGv0VIYDnuF8gTl12Ie4TuE9 YeKs25/Ja29zzGomBu2l+GxnWA9Sdaq88fd5OEQNC65urRDrykRYDJ7SAXuXvpOp BM19pUITrdIkUmKhrJQB9xeE/zE+PcRPpaJjNvN58maHiMEtPPD7Lc5eeUhVXa4= =FtmQ -----END PGP SIGNATURE-----