-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-wordpress-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-wordpress-14.1-jessie-amd64-vmdk.zip f2b918797cad970d9a287712307d76a5 $ sha1sum turnkey-wordpress-14.1-jessie-amd64-vmdk.zip 197c267e9e2718d4242bfe312c8c5ca7a1853627 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn8AAoJEIXCXpWhbrlNrtEIAMZ5NUtBE/u/CMJq6kVZDwYG a7/UbfyinRd7UIuFRuF9UE59F0x9wsX3/QWegduwFMPVN9/xECFIe1WB+ZU52ltN Mu41PfEKKgxzS6kZynfBPRV7SVdffNtGCLtpUXJ53ykQB4AWVnwer0IW4cbSAk91 FSqXzSJTaQr0YsW3TnB82WZAIA9GsAeLa/hsfDJAK6kPqOSE1VbAubZn54uYSzTX 1VQCtGeeQsAVhVn3DmnEpUSGwnoRyExX9QvAAZKW8CFyphtkpzrRmu8y4iI1++L9 jDcFzXdevoJvyiz+YSS1M7CnXXeq/VEQdyRrDirjEluJLUcbYK2vRWnoW9ujsUQ= =YetB -----END PGP SIGNATURE-----