-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-oscommerce_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-oscommerce_14.1-1_amd64.ova 7d8dc97af46fbffc8a2020c53d223991 $ sha1sum debian-8-turnkey-oscommerce_14.1-1_amd64.ova 0d90bb10801a96b5330cb6fd06f4d21b5ed7b317 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJntAAoJEIXCXpWhbrlNb70IAInUzsXeBxURpLGxhkSlIQJf Bw+n+MyIqunon7aX3gcyMDbDugKrJ6mi7AV/m2XCFT1Qv265CzLZBMv1QZL51YuB 9UWk+KpFHsbt663yVpqHvOYU7GZfFkhdqDbQLVsyhvrbjmbLu3FEAV/FsDB/CfBt 3aKsFs4N0A2d2cMeZEKnIS1X3F6iHPMt1zelZgBZ4LEQsehmWhCGTe2KS1JvwRGg LIKMSRwwgsoS53AtpQB+vfdSN/zrn4xgZ69nSpWExtHmCpfhQhoc91PrEhOGnJbb qks2Ps02YMb2fsB50prA9oKfUaz1/tM6mpVnZ0EaG/KkosTHXNllsGQW2IGP8LU= =P2a1 -----END PGP SIGNATURE-----