This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-canvas-12.1-squeeze-amd64-openstack.tar.gz.sig gpg: Signature made Wed Jun 5 08:41:28 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 60c72b252a61ca7a6f356b108d99d22f311fea70 * md5sum 851233c554f90da7cdf0e9dd8b345070 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrvmpAAoJEIXCXpWhbrlN1/kIAOZnpYIZa+mZEgsSe+Fj3TPz bA8LvzlvREwa3w40nseWTt9HoF3rESxmlhrsFiZJVsXOZ8xG4NM/RoD5BQK2ngBj gzGoDPn445lcidgKl35+LCXcY9NzUEicPHQn8EV3HKwh3jtro230qS7HQvOJ8cZI /6nCb2LpczpgLmQdiQrxslgPLkQVuAheYGh9Vd4Oo8uX2hmUz6lVekn7XDIrs5CD NernXZ3GByBea1GCPBWA3iHGQC0zj7bPaOYzyXPT/kDD8OBSikAlDXx9wpBricp1 9oFDWUV/DJ4hujNqM2Z+e3CYtJThnB0afe0YIQghSDnJ8/YYpO54jmnJcjS8LTM= =fY4S -----END PGP SIGNATURE-----