-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-asp-net-apache_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-asp-net-apache_14.1-1_amd64.ova 9e0eefc1b21bdc05c8edbf8d684a71be $ sha1sum debian-8-turnkey-asp-net-apache_14.1-1_amd64.ova 0fd0548f8efa9da5cf62d9de1695a73a7e6089ef -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnpAAoJEIXCXpWhbrlNZrEIAOi0Q481aEnTAhA1U1u8WPft Vjb9zH43drL7grfRXaQYTEVY1yOq5GET+QDjU2jD/BeX3daZsDGbwafkHk9ikZIp AnfLcOSJy/sjBz5hse+hJbj5kxXEkxZMK3hPObloYJP+HpUXeSFeDcv7B1tPFbYV 8duRU86XhaUojxhnwr5rS/kYreMu5TWaD4kkqUjeyLZDGg5kZhDoaaGK52N8eS3l tpHKikmDvLXah+XayJB6NbhQN68WvUL7kN17yyy3qF8YmPFwhW7Ws33N8pKuVDuw PFPg1AX0Z90Suq2AUv56IZsiomuhCxkRdG5XdPI6JUDWGmwDVRmkYF/21Cv1ejw= =iNtK -----END PGP SIGNATURE-----