-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-nginx-php-fastcgi_14.0-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-nginx-php-fastcgi_14.0-1_amd64.ova 9647a8f41f40d130ff6560814fc0049c $ sha1sum debian-8-turnkey-nginx-php-fastcgi_14.0-1_amd64.ova c89dd4b076a3ba5fae8803f61ad57e054d844b2f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWObxUAAoJEIXCXpWhbrlNiVMH/jl1MgMFKOe4vN1N0+3EInYL wqOqUbbcqQj9zPc4UP6bu/XyztuI5TNSb3kXjtusmzFSnSV8pzkhCxTCyhsr0mZB 8Xz1fYVPXKIWN+hYSTSCfDant0suOqLVR3Rj+lgyxokT2qNbk+dgGSjr4nC1AcAf yWMTeyjUXXRBaBX6zHUkYWU5lZ1410afegilByHRd5XTZWlLXJKK2r3dBVlzXyvG Gg7EexQp6nlEwuwa70OO6nNZo8XQuxpYBSvAgQVDF46a/xTMSL6QP8wNRE9qa06L EFMCCbkFvzZrvqk3lYUN612rXkLyla2g5N97adkuo2tnQLyWDVIhw23Ylol7Q3M= =rf9V -----END PGP SIGNATURE-----