-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-vtiger-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-vtiger-14.0-jessie-amd64.ova e8d9ec237fdfd7e17a5ad00b3fee9a55 $ sha1sum turnkey-vtiger-14.0-jessie-amd64.ova 5a0951e9d18d47617a2282995ec1036fcdf867b0 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdaAAoJEIXCXpWhbrlNG14IALl/boo44x3S5rAfjLzFUQUu 4bqJiWjDycSo4+ySvdTBMIwPG1mrcVJdFei7GjHSjM9zUiLJ8CmrZ6IsFZWjl6eP r7GotKbZHnh2XaSg3W5L6+Nb1e/QdGO02WofcWsOPjAcSmLaRnQhxpt8R4sUt/RU fw+sonHBD+VhRI6xzJwQCdbVEWWzvXIsxvRuFUiwbHRYMIrwEBde9xtiaajHlQT9 TGSxWaXvervqZvkz9Ur5dpWE40xdbYm3Aj+7exaVUkrpKISWhtewTEE0aUiT3pLm kNk350mV3KSk1r9fDKRZhQuQylOwwya69jie+kAxW8oVFVfSSUgRy8u17UkvtDg= =jQRS -----END PGP SIGNATURE-----