This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 18:40:05 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b76bd57252ce10d7fd2bcb02ac90695b27067347 * md5sum 09c2bf8edc1f105ef67d51a2843352f7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXYv3AAoJEIXCXpWhbrlNJRkH/20fsb4V/D9HjPFLpAzfYTHL AsKE7xVdcevZTGhtuplFnlletOCuWLnfGVbbltc/ym70MwXqdem5f2IMWWFgOv0t 1xtfnl6hZYH4ptmHMpm7LLqhUsYIgv6LhEzz32oSla1vK0+AyfsHgUvVyZ6jZA28 GhI/Dps3GP0mBeaP+wuFVmd/skuHZ89u8lQAeIaScZGSg3J0zq3onHJYXqXMo48q oD8gjMWCGE7B9B+lRaIEVwflfOKYVYg/C4btF1VlvcSKgPfeDRqAP89v4M16AGUl uWVwBUY6djnwTejVYD+603wSiu605mUnNYh5bMxB9gIFuYaR6FtJrsw1L4Uuu4w= =sJ0S -----END PGP SIGNATURE-----