-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-redmine-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-redmine-14.1-jessie-amd64.ova 0ffdc2ec4d0fbb7c30f2d59e129e56f4 $ sha1sum turnkey-redmine-14.1-jessie-amd64.ova dc4b3f53551eab65f63a5cf5eaadc2e65281cd4c -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn5AAoJEIXCXpWhbrlNSq8IAKwF/lRnXRbUe9EnAtE9Jcwi xMHayxJDKeVhjrXErpAfm3gJW0EnrKxA9TDhhO2WXiHWQzfmwccthmtLepmj2h4F 5Y5LlGqmW6lG+0QOUJbYbMw7AhwbaU95fRzvdnNcRdBC3PBDbG0yO1XGnmWG3sJj Uxbuc69UpzbG3bm2mZzKYS3bV41QzlEuPaHqdWpoXt5pwN1h4fi6O44so8tWXb36 vVbJow99/sXRgVt0yGqI6yNHPRxceQdx49paYc0eOEnxtSel4OcySdWQExNa5LF7 OyhDb1RFXH4wGdCvub6QeVmouTcAi7zg1Ukq2v1+w10UPiWeTEzyEK7nkdhda14= =BFQy -----END PGP SIGNATURE-----