This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ezpublish-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 13:23:57 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 372f3db35300fb436aa7609d9c0e70d69226a761 * md5sum 3741ec85648986226cbbc3a35178b773 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrepiAAoJEIXCXpWhbrlNdBYH/RkYo2PXTNjznJMfp1ITKYLE JTfQu4BivLX08U1kztxgMlxrOLNHh3K4W6Nivx+ObhVtEp7gco9t5bBGQ/2yHsfL rUzMFgsCTI53H4u7/U9q3lq9G7egA0DFujZEkxyjHlpR4FGXwV36iMrvVkX4wANG swsBiBMY3Gy/t7+5bzxmbJ2xahcrjQPXMUppGqnOrsx9IrBqyBbVNLj7zZQDbfLu jc5xfV9ex82Cl94Fn492GjQVRiW2s1zJBzr2woLaEYdoQgnfkzjr3z3tlgUMFlDO MPfLbxOrqeaWA9Quirss+wcYPW84UlQPPNmQPs+M4XHlscwx+CWED1VCAYiq9+g= =b/4U -----END PGP SIGNATURE-----