-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-torrentserver-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-torrentserver-14.0-jessie-amd64.ova bbb3f6df8fc34aa984953275fb09552e $ sha1sum turnkey-torrentserver-14.0-jessie-amd64.ova 7bc79efe02ff132a4584e313e2006e19b1aaac1e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWNdrfAAoJEIXCXpWhbrlNw1kIAMLCsrKL2bQv0RTu4K9T7Skr Ch5LFfFosv9INutUAM3AoCsuqtbSeP9WlWQgFpEhSNb2QHYuK/2l582QfeEzgzLK gJPpk52TzffqJlv9vHI/n3Gtz3N5dAPc5HbyRO0E4tA2JHfmSE+q4Hcfn6bLr72k paBVA8ltMaTVzu2p+sBV/fdWrhtkEtJhzos7W5r7FlshxV1sl/wUz2D3AepIjo36 +7C6OLh1NyaFDzks5de29u3rI+nCCNgvdkMUhru3IkhpWOi+f/bPdkyc9h5LfrGE 5b7il6jrzcVyCmGdaV5S74eICeUfdNUSOD2tQRkn1IYa8tyQ3hFo3Tu/hH590mw= =X+KO -----END PGP SIGNATURE-----