-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ghost-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-ghost-14.1-jessie-amd64.ova 4084da7dd6a4de78d0102453ca0b16c7 $ sha1sum turnkey-ghost-14.1-jessie-amd64.ova 570887ec4c3586f5364d4044bcada3f48e497adc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXRb5nAAoJEIXCXpWhbrlNoIUIAMUAFQFnjETCTNVK88EPZ9j2 m6PcFQCMBLHSB9Gb8oM4LdHJZPp8O+uphOHnbLou9+16e5zxveFU957aNKp9XR8j 91WDE1/CzWb5dN+2NHu0bFJDLsxZM+IRCzDgkvqKBrapcvxI4dKFTxVtsoIHwsS4 iRbksUCuP1ryQZVEHfupHFwm03bfR0YpUsSeVWDUz0p4lL99qEadQGTxFLB3pxHa v80E0Z2Hrs3GZ9V5kN1hLjryrE3TwBQnfDy1HeZVi+3JGU154QVZ247MnA0WIzy7 eRrLXWr0HWV6U38qzFfCmAkBIKDiG62ojolMS+HxEuDcCLrUlk36jPt44fFQkeE= =cSwD -----END PGP SIGNATURE-----