-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-concrete5-14.1-jessie-amd64-vmdk.zip a1a8ae809be598a1a9f04d4540417225 $ sha1sum turnkey-concrete5-14.1-jessie-amd64-vmdk.zip 1e0b32134396f4c4e96eb1af9127bca61a46d8f0 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnxAAoJEIXCXpWhbrlNNXUH/RExcTxP8U8DilMw1CeNJkq2 9OdkZbXAwZdrKznDWgH987cZZOH7uzjtmuiEohhmmkr/b8zTP4J3uOlUKyQo2/ld 2gdPWEBE11LkpO5eLfVo5ROd2cLyZwvLLOUPDDS0DkTsgUAwlTq/Sq54Irh2MdUe 768ibGV5ZzjDRMcOFrCq10xCbx4oZTYAHPZsKX6udJ5FoNzsDe2ssMFLiNr/TbQ6 WvSZTr2GkzqbJAaUrLHVvZvlzhERq/UR21OLu+ahQI0OlRGNpeP3wUdK4QNAinx0 vGFbvSZKDO064bJTHSs0O2a9wkDd87JKeE51FARjK/WPj6vZtDNKTiJ2vROwEwg= =57mb -----END PGP SIGNATURE-----