This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-couchdb_13.0-1_i386.tar.gz.sig gpg: Signature made Tue Oct 15 15:28:59 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e2edadfab4d9ab1b40e8698391dbabc35f4bfa61 * md5sum 0a5527de0f54e748bffb23e1c4be0389 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXV8zAAoJEIXCXpWhbrlN0CMIAIY2GOMpGCK6fu82HNP3K43+ PnT+xhYa98FGMJ5tT4GMUxfyTTZVmV6kzRAOjR5fPsPr+mVXUSaQvxYMox+pAZgl vV/TeU8IbUhuJyp6NqHURs46y4L3R4bePt5JC0Qwo+NFdbUzKHdZTrygtluR3iCr 9gRWGxIuM8STOPBF58TnXKxJJbu2TUSrBQr178cjkpF+ooE/JYK/xebdOC4zlpGY suJH4W09eUbFMG1DM3wiNRs9qxEnQrLvR6cbpWcqYFy0USUUAT8hGSL/hrkkUmXZ 0uYYFLgcTWA2onnz5F6iCppEOpSWP+ziRp+5JXGeV7IY2B35TEMwFi/wanCEAm8= =iXRQ -----END PGP SIGNATURE-----