-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sahana-eden-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-sahana-eden-14.1-jessie-amd64.ova 9d64936bd24e9a6c30106da6293cbfec $ sha1sum turnkey-sahana-eden-14.1-jessie-amd64.ova 0b3994f6faa80af7d543eaa17ce0a92b4c086adc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn5AAoJEIXCXpWhbrlNYTcH/i6wC0o/I3euum8+hgvK5rKD xGWJIZKlDioC4nM5Rt1xxO/plIilhtiDw/NaaA7Aj2PaS/vELzZPGKPO9jg8y/Yt YvNFgJXfSj8XDXpht7gX154caRv0zVB9iTYUlcTfFjJaMDxRGpgXU6BECmga1EW5 YXnwYhzaXiz6IbvZhMNlYVEMYDFfoR6DFWKicimYBd/nAQ/T/WucdMsxJ0Trltrj d8sw5kAWzFBndJROt7aZxgbUCcCuIOZd54dk34MfzPIN5JlnLc13dY9ngoSBQhB5 LAjDkq8xjTQe8YY7qCumv2RBN9gCBL3Gg0Y3vVqB1hM3qTo4TtEhTdUPgvJAk5Y= =IAFS -----END PGP SIGNATURE-----