This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-projectpier-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:18:56 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 0a7f314383a06adc63dd997151232b09063e5fea * md5sum 88afcae456a3e79757138e7ea190027b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3ykAAoJEIXCXpWhbrlNeEMIAMOjQh4VVP69i7n8IDz7yaQc 1xf26CfrdaOqSp9pSm34Fm3B53idhXR5yUomwPfo4YrAeCbjTNrpBB0Dm4ndzFTo 3YaMS1rp4PMjIBDuWkbGQ4qwYcfGnbdBETblp/UgpLdNP7HUtnSFhMzculHTNMdK LQikTqpLNHdFSbsS0NJK/Gns8tEeO1/ZUbineVTF6+gt3VmRA7SMO8eq0pdzf/Am 6EqPFABduc5O1oT6M2mWxKrmzvLMFHWt6gow/jT5fPMdy67Z4jwQYuXV1AU7aZKd 5BGhuv/ExDLd2IslMeVP8oeYGI2BpU0gydgJ53hLYx1SNq6v7HVRgdg6mGH6fo4= =JcBg -----END PGP SIGNATURE-----