-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-processmaker_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-processmaker_14.1-1_amd64.ova 6e5f823ba86a214e15c813b94abb4a46 $ sha1sum debian-8-turnkey-processmaker_14.1-1_amd64.ova f57f697d2da2e3746e32d6179cbaf4a100be57f8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJntAAoJEIXCXpWhbrlNg0kH/j2FytrnTdV53KozDiq9wgAL gEi9YCWultGQJ1VwZyM5OMt4EgZSlMd4m0uUxEIEjc897IxRWJFB5MxDANdzCmWI cw14kq1WjCTAzxwDM4Ep56la09hpe2oGl+zTrHimWLalFzQFhvs7PBC4hbRE2OKP IlxZ3JucosbrXSgJwncvuApU9GhVUM+fbt/qK7OU03kgfDVcuguNTuui88UDVhcx ODcBpKCr1xhQsQMIQ9cWoIbloFXsxJmvp4ERzjQQPhpZ6TbMY/letL/wmUDCvNiz tV6Up7/o62bBsCxIBe5fD8Y7EZmkynz4c070Jv5Zb3bYEUY3dDLDjimsZ1gPb3k= =bec3 -----END PGP SIGNATURE-----