This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-13.0-wheezy-i386-openstack.tar.gz.sig gpg: Signature made Tue Oct 15 20:39:39 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c0c92b7ebdb17b306264405d54b66390a5ec93d2 * md5sum 8b47d1018df2031d386fcf30e9b4797f You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXagCAAoJEIXCXpWhbrlNieAH/0Uh06/Yq0fGyGrBTLaN/JIM XY+f1HBMg7tUJ6e8STe1RZ6DEYY5sNhcNETLG7mm1yrfUGMXPl8MtWsHqGdQgToJ /B8zeDNwM5T9O3dIR5DdMomCtLSGttQF1wsUPnAlFHXjJ5YSc4ZjrWCytXKJwbuO E/RKISZ9sF6dTJs8MXP5hcVDAI4n8TMaeO64ZVLXEYHBbE4wFuTMvWs7IpMm5dx3 0XprJNQistCbXAiWT/pVHgkQZ3y624fuCeddnwEbPEouq1EoqTW7T6I9BoOFtW+5 6Z0Y2c0PFhkayapN+vhlwpJYEaFG9QBfDsKVU0RCalFIqyU7RFUqoEmEQqu5rtY= =ExML -----END PGP SIGNATURE-----