-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gallery-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-gallery-14.1-jessie-amd64-vmdk.zip 30d943dc0167d8e436c88eb383462219 $ sha1sum turnkey-gallery-14.1-jessie-amd64-vmdk.zip 23a965ddce6fefe9d4328d6895ac495c349c14d1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnzAAoJEIXCXpWhbrlNnVsIAIbX7APbHekRP4WJ45atzOD4 TxOw8HVmQwP4A2FtMKEoGlNzfWhGBeH/xAUIXBUZ9ZYC2cAYy8h5jtxbIS6yO1Ne 7Q42WkRZJMOcW6DVAZ81+1B9/KYihbWEdVCwWp0AFfDW45TsbWnYudoSq/k36XLj 9tB062R3eqr5NpPkzUhws3sWOqPzmgANMKH9QotSjS2hukslpCLfHCWd6mJWMW14 eL6HAB11yJPWYtfJ5BWmys2q8ovicqzlq6ClDuH1bzeJf+zdHtytUWkQX2J1PdXB k3ARkgEAU8oP7tYhGZf+tgRA1fqxnkVOX0Dvz9KjB0O/uq539TBS0feRpCWNkDQ= =31gM -----END PGP SIGNATURE-----