-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-otrs_14.1-1_amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-otrs_14.1-1_amd64.ova 4e511fa6dff192c8aa01d9ae01828966 $ sha1sum debian-8-turnkey-otrs_14.1-1_amd64.ova dc791f71d9a6c12e4f0df3c2e06e42495a1c48e3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJntAAoJEIXCXpWhbrlNaqAIAJsJknyN5uFZQBA0C+mYy8ec VzlByIbtSA+0o4DOeF/ZV1kH4c6oQzu1nCpFgSvLP2zZ+vLXCE2xPBr86wiLxMBQ UEBIIaRRVJh/PvlrBoIiBudzhmrr85ZvsO/yVsZLc9+vwoa0TIWiJUL1X6C6G5lS xa7NUTHJfccylkba3ZTz9CZ1Ioc8DFvysNPNDb83VLooq132Bz3gw7ZideGavIJn TmE8ZNo/3K+9NzD9Ir5nsegYrn0zyycCpqnOzfeh8kBYv/BwrXwktQF9/YOfKgGa JM3hl8/b4V195fa4lVgzFUtfcqiEhT84Gt06oLTeFRRDnaZ4BtTsG4tBnQZEp14= =+lku -----END PGP SIGNATURE-----