-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-joomla3-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-joomla3-14.0-jessie-amd64-vmdk.zip 5fb1285975d8f2107a4902f33c166c59 $ sha1sum turnkey-joomla3-14.0-jessie-amd64-vmdk.zip f677f1a9f650aa58bc3bec43e19f0194cd3aa576 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdWAAoJEIXCXpWhbrlNWUYIAIjtbVyllDkruiM0BGTIe7o/ hfsDxE/YZ1NrpKZ8HlXSVgnp7U5gIgfiQGpCtuS+Qger3apwhO4zR02PjfIudfBm /zjIwJzu1EPVeyoULAxO6s5Lb5aeF8/ztrIRT+z3l4DSUpHukj9yg6p1nUZlWBHg EjsqKxSGKluBjYXWVdi9ajXFfh+gJbmGxaw9TEJL8Z8HmX4V9mE8UTJOJ2H54M5D 8Q5Z3HSvZ3p+LjKn55qi5+pI6ttpkzrTE9pj6NV92VJgKpSs2YjzWCTDOvB5nfJ6 P9BwY6SVQsRWLbK2c6qKZJvD5N3L/XLGkRhZCuinASFlnZUrHtD8MazoUAVw/5A= =miPs -----END PGP SIGNATURE-----