-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-core-14.1-jessie-amd64-vmdk.zip 58c27cce3e44b2c9d2942431ff66ce89 $ sha1sum turnkey-core-14.1-jessie-amd64-vmdk.zip dd5d56953290aab8193151e58d72cf3b44e9e6f5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnxAAoJEIXCXpWhbrlN458IAOFlih2rMTJvNcEKcexWmzbt j9RjfYkCQuK6QMVItT5nBOynMfsUFGtIHcUXmBHFjMNrylwXMrdPE3DpFOrKwxcS AM4sv2SfAGl5wBxYNIZQSvkz4Maw6pkGp1G0A54+vnDbB19+8AmSiL96jBnrY90m zQPnDyaUuoBxZZmQ27uMLz9N1HsPiCOwdOPpHiqOd1kgVvyorfvMGhDh1wChjDHs +Be8vH69QR2upqCpfCU3maZ7Csr89OTVjFZwH261KWiJCyQJJjTRSz1eU3zcGm6T kXRJSM8Q3FUMXBrIIAGKBvT1DG2Ls1Vt98BgMnpf3QhIb7bXKGLMRMrzcbdCIgM= =pijx -----END PGP SIGNATURE-----