-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-mambo_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-mambo_14.1-1_amd64.ova 22a04d340696c54ead40e00a56480959 $ sha1sum debian-8-turnkey-mambo_14.1-1_amd64.ova 6b432fddaac961c0506032d2dc425e4315056665 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnsAAoJEIXCXpWhbrlN1IIH/RR6Ge10u2gLzwfDm42OVuOl DgbHiO4dnyFJmN/F4tWfYJ5ASxAGY3xk726eKW32+Nddo4vuxqK0lX1eP6uJbAWB 1D124DDgUhVeDesX6XnuYxfIYL1Yv9IcMTUtsLTOlWQVfJPlhiT/JR2qzyUFFD7a VRXTQEVrIBLYU6p78DfzcNwr+tfmxI9KEDhHcjk93PxJU80uQLF/Pw7UwalGZY79 OnJ4S+LkOClneKfGuXVGPdMDEx0A8qoknCHAVXym5FdLf2yq8uKCROd138Cr8yJZ 85GZIyXTii8Sw/mrjcc9EH4cprSBXMTzlivNx2VOGlEqzX3nhu1Him+M5ZHvAiE= =DPLa -----END PGP SIGNATURE-----