This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomatocart-13.0-wheezy-i386-openstack.tar.gz.sig gpg: Signature made Tue Oct 15 19:39:08 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 2d3919cc86d44aeb25937d3095d5ab1b5cf5a2a0 * md5sum 1c81c706c2977d365fbcf74be6592851 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZnTAAoJEIXCXpWhbrlNIh8IAIgS5oL43jAAMtZyzBuEavNS WnUOYs+hUrBvLryTJCQwS0YhQUquMx+v+mLemhDsEf758QuMme9NCjdsz83V0Sos uHvOw6fqnoZVDFV6waISu29smK+BJWoCQzpVnKq3EM/DnJ+hGCEChwP3fkMCzvXl VAJxOGUeJ6bDzR/U1a1XW3JaUa0nCyhksrr/wKgT0WpS4wXSyieLZnYtpdWElwjx NYrXl5DlOt/A190a4VL74YoTFvLWVOfxXmRrOtyWs/RqLH6tqHJ1JEFfAsw3yT8I sOd9qOAONMmJerN1FsZP1M0nX+gsWROB+xftz6tH/DxJpTx9vWdEidgiVusqBlM= =swKO -----END PGP SIGNATURE-----