-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-phplist_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-phplist_14.1-1_amd64.ova b5d6be5caba45bc8c1c335e990b1eaea $ sha1sum debian-8-turnkey-phplist_14.1-1_amd64.ova 9f09cefafc19da4410f6681a61094a7010484d2f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJntAAoJEIXCXpWhbrlNUREIAIh0Oaqy1y+EdegbITH7Vgit 15qKK5uKFUmDZ8s8j4TfmohUhKIjBkIPVxHI2LwlCM4Yx91VqeFUtf4VJa3Nhuk6 KnFLOIP0w6gF0v6YncdHiC7aIFivtnrWsNxQxAB3UqCe6tZvkgM9Mw4UY325CL6H m1Kb6gDAofRrOWaWuvta4h6Bb7mPc/rQUbu1CPXohRXcRZ6OXG6ilZuId4gwceC+ 6hJkyP71SVG9nfrsz4ABHDy6fv8gPaQOnJRYMCfLF35zCPv9LRV0+mj7fG3TU+RF fZiXDkP19ye2wrOtspGVYXRBqSBa9pyY9BwRANsFDIE1LvWG2Pp03e3NnwJSD7g= =siLz -----END PGP SIGNATURE-----