-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-simpleinvoices-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-simpleinvoices-14.1-jessie-amd64.ova 157bbce701aee8d30ee945f7773b5e1f $ sha1sum turnkey-simpleinvoices-14.1-jessie-amd64.ova cd744a3a793d453bd03bfaf6fe726559cf4cc01b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn6AAoJEIXCXpWhbrlNXxsH/RCYUKDH1kCZo06xQ3MX3YM+ hVck7B04iqQAK6J9aOClnCYeZq0mzZZUQvtQFlU5EQQp6r3xVbuOGZ8SugKcjLHw 43oSpdpq9Xv2h8mnkoYJ31qj96FbijdU82NlpezpHtg7B6EYXNXo5ngWsq8B0Ugd C5JM3qc9d2eacwM/NOiill2Ld4O0kT7K67Lzz/k5i66xU4buxwrI3atzkLQ3jbUu Vv2sUrnSXDVR0Z/VBasYzdNQ8GyCw7w0bNEbRHXkF6UCSLxeWIIr+4LMsUiN5DTk DfQimLF45Jemyie+aEMAID0a27DAY4zhBy/lLpNsMGZGnSXdeb/l5EosrrlTaG0= =w0qH -----END PGP SIGNATURE-----