-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lxc-14.0-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-lxc-14.0-jessie-amd64.ova e0f6d8d501e9e7a9d8a08c048aabd5b4 $ sha1sum turnkey-lxc-14.0-jessie-amd64.ova 688fba7cf84f04f8c4d68dec8cb1ab570523b1b7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWnf6zAAoJEIXCXpWhbrlNsBoH/3BwLowweFA1eccLXoCp5Iro W6EurZEglIQCjJnYVErp94OpCSi4A5TUHQUSg4lyLcBCr1RTovFbGF7xmAEzh4hs pp1k+OaLC+W8qXk8LN5vloeSfzWlnzszy0TCcV2IMvq8flNbmhKK+Mo2OVlnBGXD 4sFLp+5HGRCUsxB8INNBxdheifDaVz7WcV8dxNVcwhwDuDAwZJCQ3FVjIysyWKc4 aE7Tcaw/7vIeElSQm3hQNYachrAoOAw55zQZlUdaEROjmhlVgdrHNU8VqXO4Po/v 360fiQCXEm1Zy9U2VusMF5HgGfffI2mBQdNFt5X9TAciZwiUsddF1C9efO97WzA= =OM0Y -----END PGP SIGNATURE-----