-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-ansible_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-ansible_14.1-1_amd64.ova ee5adce9b04df872e5a03060aed5a6fc $ sha1sum debian-8-turnkey-ansible_14.1-1_amd64.ova 69084ace5e116c8aed55b94e1a6dc7874442986f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnhAAoJEIXCXpWhbrlNT7AIAOKea9ANIOBSoir5R02zOIA6 JCKeIAlbA7GZ9k2HG+57poi1HXYBO4uilB/mluqf30RWdscoH0ZTjsf2XqpBU5uY nuRvf+DsaOqr+MJ1+Kc/I2E30vx0i2aZJdEHCQ3KDG9SnTizItYy2U/d7PGBAlDP VRJezzKousq87vWTCr2mTz0B4ckuOh8oCc9UjJlfofkgKtugvT7ElSc0gkT2GJoQ ki6YiPFa+LDsJ5SQX8JnejqmeJBf0Rpi16cgJp11yXawKD1duTEETM5uhYhQPauc efobVJRdHysHKOdQE9Jnocmqxv3JtHifhfHWBhL6GJNIUwGC+8PGqafCqVEzKVs= =bjno -----END PGP SIGNATURE-----