This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomatocart-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 16:36:40 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 532e732c33b9f3d32dcacfdb12a04be0d3b5d4f3 * md5sum f2afd5905eae6c0e204aa79102ab5fb7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrheRAAoJEIXCXpWhbrlNCXkIAOTvjv5efB0AVbh0M+wGFZW7 5IBkAMGp4UJyHA/0I1XaJkkAryWnlhU0nV+R1rnLDfToMBvdY40jm1tzmPaFtDCq NCMrSdyvagih0jdzUV1aCd/WSqEqKIYgJ1SR5EEM0EtTQCQVQFnlWowQzy4z7dWW FUyXj5gi71p7QiwSRlw7oLQ8mzEYerAkXwI6IVUCvWO9JlZEpg1L2RlsXAxH2i3h Z3vsmT6mmMFDZwICiWruljdGzid4GHEordMXBlXHTVs+x3hwS5FEcfvG4bFz/E9d 6QJyo/PtiOzpORJ2S7mlmBtgdvwE++EBNOjrWyiyge1YUUsf1HZ76I+byb1dBms= =qNqc -----END PGP SIGNATURE-----