-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-owncloud_14.0-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-owncloud_14.0-1_amd64.ova a972cc7bcbf6cf96d8b1a6d47387eef0 $ sha1sum debian-8-turnkey-owncloud_14.0-1_amd64.ova 7447ae892ee03727034d28ecbcfa93d524d44946 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWObxUAAoJEIXCXpWhbrlNrRgIAOcuVn4yh8Wvl10NBJ1jcTLe mhLHcW04t3v9KJQ4SAWfYbLV2vspPame1fk5oR6k6O8JfAVyj2OA3YfQOt0kM76J xmiDc9SvN3GOMY1SOIVWb/GpNgBDSC9ReCP+WnOe354QZkvb/3LbjwRt46P7d0iq eYM55hkvNMkFvGbw4Ca6WiMyWCqKI6Q6/WkqNBAur5b2MHfnyMp4iBHCPYL8+H9G KHQ9WA5ro0vVoxD3q6epcGZhsqgy2TbNU+yuJGJUQvKsPQ2M7drLw116wt9Wsox/ F+JlRCvFS5igaQFz333WbHofbnuRUPXV4lxDuomkR99jh/ljslUG5pdEPjmLXTQ= =X/F8 -----END PGP SIGNATURE-----