-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://keybase.io/turnkeylinux/pgp_keys.asc | gpg --import $ gpg --list-keys --with-fingerprint release@turnkeylinux.com pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] Key fingerprint = 694C FF26 795A 29BA E07B 4EB5 85C2 5E95 A16E B94D uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal7-15.0-stretch-amd64.ova.hash gpg: Signature made using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key " For extra credit you can validate the key's authenticity at: https://keybase.io/turnkeylinux 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum turnkey-drupal7-15.0-stretch-amd64.ova ac9d30a92e6e9dec3083223f2aacfde0d338df82f31510a01ecbe065ab987601 turnkey-drupal7-15.0-stretch-amd64.ova $ sha512sum turnkey-drupal7-15.0-stretch-amd64.ova 07b47682801b4f2f555b668241373c15542b2b8ab14d8ab9c043384f4650d08ff8a1265a5907573cdb22f9d4d03d53a68e34e786236b5095dcc6a134eba8caec turnkey-drupal7-15.0-stretch-amd64.ova Note, you can compare hashes automatically:: $ sha256sum -c turnkey-drupal7-15.0-stretch-amd64.ova.hash turnkey-drupal7-15.0-stretch-amd64.ova: OK $ sha512sum -c turnkey-drupal7-15.0-stretch-amd64.ova.hash turnkey-drupal7-15.0-stretch-amd64.ova: OK -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEaUz/JnlaKbrge061hcJelaFuuU0FAlte12EACgkQhcJelaFu uU1XYggA193g5pmak8DUC7T89lA49tVyreddtKjRkOdOebpOGjOz4QEWaRAdo2Md PDh2w7DlpfzcoOnhuhhUASYWmA06kk39xZKSB1JQZIPWbzv9XGIiiGH3gvJSOayb 8V3SLBiRcZSSYyA8icVxVtO61+/Ykz0RqYFiLSbk+e1imKIUKWMGOYbxsTbM+Fu8 99r4tDRG4hDp+KO9582bO9jHcVbmy5mfowiFd1jqU/Os1Q2KIb1PykRCKToQpGa5 IEylBee4Ow13ur17pf8Nts0SvXJHdCQXHvK3w9YHa8rQbMMD62XkB00qYLT4CTXx 2L4vogLNwW9ESezVGEpzvLOxTbJowA== =rk4w -----END PGP SIGNATURE-----