-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-symfony-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-symfony-14.1-jessie-amd64.ova 2cdea9b7a611099b772d64b5e1ae7d67 $ sha1sum turnkey-symfony-14.1-jessie-amd64.ova 5e6f7d44bbf382ec449694fb623e46f60eea5de9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJn6AAoJEIXCXpWhbrlNtGgH/j/Wk3XrHIDnt5tQBjkvFwaV aewftZnjTZXMKtgHGUkl5l3TBUqcUv4aVwkQIBJrN5b5AB8tailyMpyNjMvRBi6U EYEp+PyaNZMTnQvLhvYQT7pGBdOdAC4Pl5jbO4fLSg8ckEwiM6R2Saqvi31zo2nX 1W6+/WVs0/hI10YEOG7yfpF4qcJR6bdPh2846EJrVmeYoybVkfKaO6fycwSpUEAU OaqmbpdA57I5KHd+pIyrBgTc55FzZJp/x/mgj+Osw2ZgTGjqlLisTpFs441ddr6X o8WgqSXrxZg6VFgETFB5WbmsTDzfbY4F8PM/LQVPAP/FFp2EijMdaBAseDJ1gzY= =Wv82 -----END PGP SIGNATURE-----