-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://keybase.io/turnkeylinux/pgp_keys.asc | gpg --import $ gpg --list-keys --with-fingerprint release@turnkeylinux.com pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] Key fingerprint = 694C FF26 795A 29BA E07B 4EB5 85C2 5E95 A16E B94D uid Turnkey Linux Release Key $ gpg --verify turnkey-zencart-14.2-jessie-amd64.ova.hash gpg: Signature made using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key " For extra credit you can validate the key's authenticity at: https://keybase.io/turnkeylinux 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum turnkey-zencart-14.2-jessie-amd64.ova 327c93b0cad5cfc5ea6c927583ac3b5780971a8d8969d910f39ab44584d85cae turnkey-zencart-14.2-jessie-amd64.ova $ sha512sum turnkey-zencart-14.2-jessie-amd64.ova 633eb7392cdbb34f8e547510cf8af7f66c6ed17a9d1a0c952427c418701166e91522f9739b53d1206e4b6c2fad0c60c4e493db2ca2080aac3bf2d287d5e45f5e turnkey-zencart-14.2-jessie-amd64.ova Note, you can compare hashes automatically:: $ sha256sum -c turnkey-zencart-14.2-jessie-amd64.ova.hash turnkey-zencart-14.2-jessie-amd64.ova: OK $ sha512sum -c turnkey-zencart-14.2-jessie-amd64.ova.hash turnkey-zencart-14.2-jessie-amd64.ova: OK -----BEGIN PGP SIGNATURE----- iQEcBAEBCAAGBQJZeIKmAAoJEIXCXpWhbrlNuW4H/i0FeSkAET1sZyuGAsBqORwJ DhnMnqvIfNyT4Es3hCNy6KkiX9IiAV115r0MBtnWse/UO3T8QllWM+jQOiMdRsxt L8fbCuuhoNcY4ZVIkEFnxh5wWtjkCz/+1PdipZeNCvBxIJ6cc21kSQwv3VHbK2gk 763MY0vObNyQMLkkkrTQ56kbREG0+uHfX3pAbVAGpFq1EM+2ELiYP2LISxMQyTcC oHjMDLMmYki3e76e1YQiNAHw6B+2hY7/Y6I6qCQ5OGphRKbiF6CW5ZgILmfB0xFE ZiT6AAiq6/nabzyLBk0aNaAo4YfxNYT5DURBzn+4M5hlvAjn/O/kP3oLbp9SRuo= =buM4 -----END PGP SIGNATURE-----