-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-postgresql_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-postgresql_14.1-1_amd64.ova 8835eba763e94223837106e843edfa0f $ sha1sum debian-8-turnkey-postgresql_14.1-1_amd64.ova 3c3357112517e58c32cfdb64ac153c4549879cf3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJntAAoJEIXCXpWhbrlNE14IALTje+kS4yRDfdtT2sl17kRs J9xgHDXLgFn4VrEuHiN8XaqWqWn8oOypwMZrqy704/hgldK6jhkEeA8185OHLz1t fzNTQOVFFJPStka6WqPlXpTNapclVanZEtX4cxQ0HxKxpLIqvBpwo3sj10EfbiIT MaJIUlcZ8EG9F1JBuFrckeTyhwYHTw0/kcXIY8QbSZdKSyIr+KdF2iLQijrar83n TNCtxPoleRxWEw2drFAgwGq8Xbqt+83SwTC8WVcaiZ+pyRaHPJsrUp5vSIYyUJhQ A7Fv4uZww9d1Z3MJWAyJpI3mRyb0lD7GUmZmdgFtMDB0/ebk+lPyho2tUJnmjIU= =h0Y/ -----END PGP SIGNATURE-----