-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-plone-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-plone-14.1-jessie-amd64-vmdk.zip c45b9a75cb9e17b6a8523037086d34c7 $ sha1sum turnkey-plone-14.1-jessie-amd64-vmdk.zip 7259478f3c9c4e262586171761efd436d7a5ed33 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn4AAoJEIXCXpWhbrlNU0gH/i6/nh1Zu585YSIq4Yi+GMcX kaqy1H1T6c3zCb/HjEn0NOLl/FIcxyFz+KOVyIQEiDUWpNq6voy9aRJmEeEYO7hP 1WMtgbAONIelkMbbKKR0eVfsX8nCZfQyYeKMOpPjzS8CgWxsgk+GpUV7r+T0jK9W qfTfevjRpDmeD9SknVjzR86tsTsTboOTR9rrh1AtPrOluYJ2h8LtjKMKAEmy0ZXH cteg4ZZVvW7IOm5cuLWzoJSTHDlbMDO8fpwiqCLw+t+bDCVYi0ZqAhC0QNGG1sPI Lc6FHrF035s7Jxo5OJmPWaUtiQa/Ad7PeFjxL3if8J5YKp1sPvRpA82dOaG1HHY= =aVYC -----END PGP SIGNATURE-----