-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ezpublish-14.1-jessie-amd64-vmdk.zip.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-ezpublish-14.1-jessie-amd64-vmdk.zip dc98dce8104abe4aa2a797be0d8af052 $ sha1sum turnkey-ezpublish-14.1-jessie-amd64-vmdk.zip 2451c0a187f8f4af51f521a0f0659c80188eeac8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnyAAoJEIXCXpWhbrlN69QH/2kgcReFDlIUnhEP7/gwn9P7 tQPiOlmxeAKtThMWzgKK59TmO2DNLkrgBh92nrUBZ4z9h+f+llvPD2mcOsnYOZpB dVKV1Y+LVV9esXTqE4bU/ksWprKFelqLjpNNkpWfp0bL2AYoyxrsPamJN6iK+3sq eX19naSBSkI0spm8tZI0bm9piOBL5UTzSvub8nM9BxvEKhG/q46c/W19CEd3OQT6 xi1gyNwtDJBpIql9b+H/U1ZfXyOaJrmGAujJP8cksjYy3eZQCs6Z24qtEHb0r09E 59p0iKa6Xa7zGsbpJhZutLRrhA3nqiTgiMnEoJ9TnTwkMb2SmIOcuk6Dn0coD4I= =u53I -----END PGP SIGNATURE-----