-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-simplemachines_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-simplemachines_14.1-1_amd64.ova dec6f5d23a3b64d3f236654f9e126eb0 $ sha1sum debian-8-turnkey-simplemachines_14.1-1_amd64.ova 6f5766e5d84bc803abfca3efd94bb7c62de37281 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnuAAoJEIXCXpWhbrlNvrQH/1wZMVKr8fjZjiOXFmAJql5H nNJfxlk/Fj/Kqjis15P+3Nel8EYyVWTwdSU7ofgjDunEaDrbdyfBzcwl8XQcTDms RwKJui/7Cs9Xmh4IAEOMtGoGHkuGCTJFfdogaVGPUKvS/cPaL5TMhoFqy0GIX84V FNwTuRY9osfeSwKbW6DasmXdk12gNfvLeXfzPjLsIm11vF2HYjSEiUnwdsbRvI6A 4vRnPl6bHk2sGQAaFWBA5yr39bN2IO+W36wW8mdnZ1Q5G5J8J2iuTZcaQOHc5uU4 Nl+ZcUXD/cK1Nzgfl3+YQD6qntoJCJbRGf/IeJ7U0M4j7KPJG899Cv1/kMeL7uk= =i8Yr -----END PGP SIGNATURE-----