This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-oscommerce_13.0-1_amd64.ova.sig gpg: Signature made Wed Oct 16 09:36:46 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 612ebac5d7f8abf7e0a523a2168fb95c45215241 * md5sum a4f48cde062a13f2cddac737568a3f29 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXl4oAAoJEIXCXpWhbrlN/O0H/0L0pmEGgwbUuNJ1B64lwqaj gmeJudS3vRUP8UcOzkQy3noJAiVBTSZEvWHto9Q8FmzLGxKNOLwHeBoP9ffvys5h 3hPXJKSr74v0x1cMEs2e2GEEtkw5F5HqltRq2G90MgvT4CSl4DkjKRgOg1xKPN3W fTPsTJ2OgOtdAWB0OYvMDdF/K7x/iBsVouwHKr2Q1+7dDcJA6+UY/JLjaGRQ8xM5 FNCaYKwFemdBOoRYopKnEVcTY7K+SlHHfGh39AwBn7pszu0mHvt7oc8jBAC4eh0C eMZB3q8hoh6+bXHw97LeM73dOceKMo2WwWZD3nkVBdFUGtwsaW1Wu6k6Ym069Ak= =qDra -----END PGP SIGNATURE-----