This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-13.0-wheezy-i386.iso.sig gpg: Signature made Mon Oct 14 19:03:40 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum cd67a2dd8b0135f4ced6f6f2a4b2afa8045f9938 * md5sum 80bd1c617c24e2a65af6e7ca43ad338b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXD/+AAoJEIXCXpWhbrlNBegH/i1flIL9nd/f9OcJ+Ht89pZw gsaZk3R7YWSoGC/rYVchPCC6QMtc5W2Ew8W7vz1xJ/G7YOWGemhb8jJunp1ieXm8 wcLtaa58onx8d2dOwGYcVbK/LHcPrTiVJAff42wq/6DlqKLMTpRVrfn5IYYvclT0 i1vM2dNA5wh8NdwGMQjmuza/FDf6MD42CfLOhWFqs8yFtAqr/Sv+K2vH7r8sYlcQ Dy0pyxTSFYyZ2fkRbXSa5JTuqJsKnek/4OavAhajy/asu+4DwabrN5nPsHGpi4h5 aR3YNmoCVefK4ITARkGGwzpJAhF2Gu/ruX9L8tM4XT2bvKpaHueiyoQTcDU/5C8= =HO7P -----END PGP SIGNATURE-----