-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-prestashop-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-prestashop-14.1-jessie-amd64.ova ee79e0ebba0f7ebdb301e69ae64c8198 $ sha1sum turnkey-prestashop-14.1-jessie-amd64.ova 7355acddaaf5d9d601719e8e930aa4c1cf6949f0 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn4AAoJEIXCXpWhbrlN3VcIAM/l10UmuG2sq4FYtiX44AWb Uq0FRMMS10zuGmYojvtquSjWGDROIa/tjoEotugFOx/Yown0Z4BTr5fqckN5dq1G ebqwEye6a1OI1PG+vtViOB9IimpbzI7Qpizpp1/bSqm5VWBcicwS5g6TSb/t+EU2 6xo2C8bUjV6DRB5cH6OSRwFYpy8S1v6cIxk4VlR6Uu27mLn7tvV8PwEQwTHxkntG +cg71Xjsq104lXxXijlFZkameucO8oG/26mtCP3PAtCIq3vg42uz47o3HRSzcdoE WVJLP+nhMPw6EnPLqSBR/Mwlm5tetESIZplNlIovGG2botms5aPeeqG7tv+IVrk= =7zSJ -----END PGP SIGNATURE-----