This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-go-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 11:26:18 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 96fb8fb9d98450192c2c60f58bd73c494ced8090 * md5sum a4402cc1021f41d218cf81c07e6e7740 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3BPAAoJEIXCXpWhbrlNkgsIAKvU5mNcdCosMNmYPu7Cn6KS 8C7bwDNV/KdwPGbv4WbOnxB4SqJiOdaxS7nqGl7SQn2JSRZ3DLr5Pqij6srOjbcx VpDeaDl0s3lQ+4X1QxADNMEc9o55AI/Y3QXLLxkDIl4St7TyQfdljTCJMu/V47FN TtMwgifi4jm71OlumV9iDp8rULNhKMrdzo2ZZjqEQK+F3Df+HT/Y137Rajr4WznC i4uko0k4kmYTkYTQsXv8j5d9RsAvliT6NsrCkKLtptFXBGNdnYg/9+hevuCqzI6j D0mGCjZ7En8/JJCgdG8AOp+tXKufPL+ykz/3eIrcSSg3HqzgjaienaLpqh31Icg= =GobP -----END PGP SIGNATURE-----