-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-web2py-14.0-jessie-amd64.ova 055d87bf4817448865b89391aaf3d051 $ sha1sum turnkey-web2py-14.0-jessie-amd64.ova 750e9713571d8d4f69e7919fbd462bba8c5c7285 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMJdaAAoJEIXCXpWhbrlNNhgH/014PjYOKSBCufJ7psVKFYqW 653kuSVMAOIb2dKesI5aIvXPIGpYiluNopHUPqmYEcG+IjGPqCQTobUgYn2h1JZf NRxILDN6oAJuQnJ2xoPrckwc9UguYrYId1kIf8nRsZQvmQEYphQ/LlATO5/RD/NJ KmO2+meY2Exoit0y3hDhStzT/ALTJVnmuuwfBxj0u+P7nuX1GX95iDbrQGJjDuaR lLolAy5fXhtofqtUNdBOXo6E44Ymx4wdCLZKmB/HbYnR6Bc18uMrbC8dNUVr5J8U tKDqB9BkS5nMq6q06Z3tGWyWcJw3T2KbbR3R7EsoWgfPBPgQ1UifOmUh/uVMD3Y= =KfKK -----END PGP SIGNATURE-----