-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-odoo_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-odoo_14.1-1_amd64.ova ac15c39e6c544b588b92e4799a3360a4 $ sha1sum debian-8-turnkey-odoo_14.1-1_amd64.ova e2d625084222afa5a94818333b3c8e0685e51df8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnsAAoJEIXCXpWhbrlNzjUH/1R6QkskO5YQfRzgPqDqxq2n vn2xac9NmA+nqyIJNda4EE4KsaCBR4Br5r6eg6+QFcY/YLQZQkmJodUPjv+0y5mC XWFltwycwAI/gmSZlwakXg51zAL+Wa0A24EYpTcnowvFckfzqhTNr8pTaJxaXgos Ey3j+7m4bT0pOQdVAnxw2QBomAZ1uemNJ0KRKV9Yp2kBuPGAHs3XB63dezxli2dO Q2rAJdcZOv7TuDnd73ka8K8FYPQisoByqO45TFfs3ZeJE5td/3WH3D+1JFZOiKat ouGdfKKh77S+oxewPFezLakXxB1KVl4dqEHqWcJXt7kSGLi2nHu5Z8HO7mYhPSQ= =n0cd -----END PGP SIGNATURE-----