-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-jenkins-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-jenkins-14.1-jessie-amd64.ova 94cef46e62019052a24691befd341502 $ sha1sum turnkey-jenkins-14.1-jessie-amd64.ova 4e9fdc1150e196859c6e265f072b890a2c0e0d9b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnzAAoJEIXCXpWhbrlNKe4IAMtGc+UMsu2SUmRecq1LCA12 aa8mzvaP3tH1SypQ2CaTZ6Kmr6gXHh6uswjQjRMud1OHOT8ZBRejMaXjYpRl6EtC FgewpfZ48xWxzaOsQ6QTwXjXUe36w/PsQCRFj+3Hnoc10wpGn7RDskHuOhVnDsU7 dlnHYp3b4JmXmsl5m7QTW7WTSr6EkZ2sh0/pfYyEuf+oflIpF7v652z3X5eHRJLz PY90TNF1tksnkOSIZ1LouXg0qbXYdcCEO3pPCnlQbyhsoy0BBgufZoaGoMpd3IMe r9glQgscRZn6+goquVUdrVbSWSvQ5sDWqT9+ks/XWEJcazBGejfSB8MOJiElSLw= =Bjcf -----END PGP SIGNATURE-----