-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-b2evolution_14.0-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-b2evolution_14.0-1_amd64.ova 8376793304dbf7d12382d999d8156fb9 $ sha1sum debian-8-turnkey-b2evolution_14.0-1_amd64.ova e04c0f33ed191cc0e57836fe7945d9c4ec1d0eaa -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWObxRAAoJEIXCXpWhbrlN3D4IAKUFyr4avGDb6meHsnIIOgoA wHMCysBZaMCDryGlR2RvKzggVMdnkGi4EvgGX/Wy0tuqLe1fxZA6MW6zV3bg8Udd TkvtfwjOlaFDGPYLfoL5MHS58T9EkeoQA6JTMW/oKTFNGdhV8ffRgz7x4HwZBAJq 7mtR5Ty7P0jbXWhSl1K2XR1Pna6ReUsmnqn/ZyJO3/nQOvk4cczif86Shml7A5dQ Mq8F63NZwvcMIih8n1pBbR8Re52Esd8VkiYwK+cLCGTb7A+DhGFMc1EiFf6nghIn WN2W9poO8BHS751Mt/sLGk6YKwl+NbBcjcPBiYYgV/bwKMcd+fYPoyM3gpgmfQk= =Zxwq -----END PGP SIGNATURE-----