This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-couchdb-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 15:23:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 359c471912ff1689eee13b3a9f623b6e249315c0 * md5sum 12fbad895f2b70454118de2037135167 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXV32AAoJEIXCXpWhbrlN2cYH/0X0CAsjtTvBHaGWbd4wMy8e ccEuKZi8CWzTki5K+gwWshGB88qyoPR2qGzyC4858nSCDT8HSimtXiovYVfyLKBG zH4N7VwfVWJDc+ylO5pVNOoVVxI5wvoEIDfagBvk+66Uq4cSPA5SNDs3h/u8sEzj lb8gg48Of1/wL8CUOXlvyYsVq8alKFNQRPBovZkItUG5DxqjRDLPcC2KsSx+4w6u icmekQRtGkQUBfKjAOJ1SG4tvyRi2lPaXgVr/uz5CFBaCqHByXm9rqOPz/TOdS53 o1D/ovTaBqaQ9JudPMC3hSvS79lhZoFFRWDP8l/tYgoJXfPRKVNTgomEqyHbGSw= =b9b4 -----END PGP SIGNATURE-----