This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 12:23:38 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 38c3eca11bf6a7cb7f82bc12a3835872a70c8b33 * md5sum b348b81d7b7fe287c6a467dc564750ba You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrdxAAAoJEIXCXpWhbrlNFc8H/0qBvPax1YgP5qpSqGjSRwCT /+r8BebA5JUCttlJCvP/jYTuaxhHEZfdXP41xTumAvIsuYmTAG8OwWPY67dNHxO0 OeW9SjaADbRIZivH1FhkLn0JtGxZQPC/sr9kPwm7Syruu1aEIaHQVMvvOn6QAHhv oZyfISVi0BdzgE+muq8I6TjkCAt8vO7EKXGnfcqd+JQQt4WZthS8LVJuMrotuvj4 MnQwVnOrYNNnoZ5QQKhs6TL2JVm1aqUd2CW/w+YHKAfJe9bz8fSfOvObD0i9SVOM gBqOtJyBF4gH6DGS697Y4gYw1q6U4iJgkgT9w9dLGsiooSF2lZQpdlupDYbUiQ4= =fM5e -----END PGP SIGNATURE-----