This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appflower-12.1-squeeze-i386-openstack.tar.gz.sig gpg: Signature made Tue Jun 4 20:05:35 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum bb8d11ea4566b5792c737a5f64bca983a49348b6 * md5sum 90000f8f4c7a9cf82a28463af4692ce2 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkiAAAoJEIXCXpWhbrlNC38IAKNSjVa5JZNI+vzxEVZtke5o 8AVYbr1SnvFMG8gQTE4tBSq52+qDBiKbc/1BLS8M1JhTHrFFmj42RF9Y4Mvf1O2H fo/naKr9yRkrF88CkvjgqJ8YmoG2RhbsWgozjIXers4JKmOTJM84bZ9BvDk+BxUN ktQNhy+O3zV6II8850ZaWeSdWHR7oy7rjmMYwgtNFTirKtu77T45I3VjOlBw7jOH bHyiFaof/f/th4rUEHQiYmYMWor2RlRwYWonE2CJXzHYJPWxEnIMZuU8+UOP8qaR X4znBBZZkIbqHpymUJpyCROKFSVvaXEfK2YN/gtYcjsIiPbH8AGPVir7k9lJvuU= =/7eo -----END PGP SIGNATURE-----