-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-mantis_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-mantis_14.1-1_amd64.ova 426f64ca6a8195d5f0a0a93a812d8c2a $ sha1sum debian-8-turnkey-mantis_14.1-1_amd64.ova 796ddde5fcc2094cea18a1c4987b2fcd6b214a11 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnsAAoJEIXCXpWhbrlNGFsH/RdHVuG2AuEXP/GR1XjQKZDa lnsWEru1nsg7rD1Y9u1kb24CgTmWn6g7Bpoo/tBB6V31magtsJU14xo8wAvZ/3/0 G+Oi4+YPt1IlvVqB9ehmFTL64GhTaTiULyjDcevPovCixpZF3YjSRRcWPyTimyoU eI13AI0nPllLXm/IBQbrSJNIhDNYESTjvKgWZcPOBm2jSl2+4wb+Z+iFTRazGXoo fqP5W9jNbuiSKXLcL04b2NvLyEXi053VhvTMxzgHSprUej7r7bmIxNDxlt8DtK2o amhIw+QhB4wJeDlE+jUz/uOIvW47KbixDFagWvVuxaSjgx0n/k7WsAsAgETTGVQ= =IHMf -----END PGP SIGNATURE-----