-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-projectpier-14.0-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-projectpier-14.0-jessie-amd64-vmdk.zip a98172bc81e2d04d036627fc68db3a7f $ sha1sum turnkey-projectpier-14.0-jessie-amd64-vmdk.zip afe4657344e4ece8bda2d954b5f632fa47f144e6 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdZAAoJEIXCXpWhbrlNho0H/jenBakaL1qRSDU9jBHKZXqt M4SEWk4h1vAs+9zAgukABk4oIx1xQHu41O/H+AaoQpdOQfe+Z4syAKrXi2pXZ17O WuRIlDkREHL80tNGS6iK2eaHrkyNf/B+wAr4bime2862YU5tyJYcyTNP0QRZ4jm3 WHEV++GTUuD8KLdAEATrf678PkFVhayS+famr1QTHPo0OJHF59haGg+eTTHDiIsC 0vxwwQ2XGVCViYFkrWM4Wtm8X7JAEQ6Oa1QtF6/WKFqXi9kSp8tozcdIAXyQRR2q APLreQTm7DZMKg9fvNDO4rSraF5hX03iPB1l2XS3Hjt4FRE4/L2o2X3AvIVIF1g= =ROLi -----END PGP SIGNATURE-----