This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-postgresql-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 23:18:53 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 37021d8a32ed6e0c805abca4521ed7c09f95f0ad * md5sum dbdef5db5ab11b595802fd09a7c4123f You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnXSAAoJEIXCXpWhbrlN3aIH/0oMWqcYUsimWhsIklMQDqJ3 81zdWUxL/RoH5v0+VHBtX7GSolqd+KIMoE9+5ETDL+A/+0M90fm9KNUa9RQF++/v YPt8sw8mzRJ4i0/A34OxM11/3mQP5sOCSEss8ogirZKDqTeV+vbaV9q4x0ZrfH7W f8lwIop4a9q27/dYRHv8ntSSGSsJ3DCEQuWrJAJ3mnvKGHNiTxi4EQsH6IPm24IY pr6mQADeDfsJhemNMkUf1R0BrJ8cfRrsIfen6Xg+ZBfp1Hcj+FLF0Gnfmrz5W2qQ v97xiCtJIp9o3R4aiA+AchYcYxT48AfPKSOfwYdt1ynLmByKdlrfjS30BVQqnYM= =TRCl -----END PGP SIGNATURE-----