-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-simplemachines-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-simplemachines-14.1-jessie-amd64.ova af15b759c8988f1cf63ddab1a4709079 $ sha1sum turnkey-simplemachines-14.1-jessie-amd64.ova c9a9e5ca280166e071354546a3a8a599a3b62fb7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn6AAoJEIXCXpWhbrlNDccIAN8MM2CffM2gqXTI6tiOGTGR Fleb+Px3Qn/lOA9bXbTXg0VT2NMTh3k2mXB9HPbLwESpiKaF+cMwuu6srjVB8K6C xHQnqRWavzGDk0gJIM905qEDJJVuaJImHutQNgNH2aH6CYYELfyHk4tpIvHu5Ysx jWyirKjVijfLWT3eCP2jNn0gkxfed+d8ZJpiNJIthoeB8vtgi3jzMgkerOAewe7Q mn9QlvTbMZzjkRKlFpjEKS4x/m0vzZTVKowub5WIhJ+eFFJFe2P+OCloKIMriwfE bZhPClnL+bTciZFk73QG4rrf89nL/QcVWEhZA49IvXqc+ZNJRmMCQ0JNAh92EAA= =fs6r -----END PGP SIGNATURE-----