This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 14:08:10 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 93501fcc95e06f73ca6343d0359941bb6776d5df * md5sum a560856f0618a03275e0e61861dd99ad You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXUxAAAoJEIXCXpWhbrlNEv8IAOy9hTSiWmyTgbgnJ9Jc1CR4 5lFwDmA02E0xHrD1Wdw3mcOjPiPLS/OTzJiDqPpl1EPcX1it0fCDnJd2c3VhRoKL do/qJLE0LHEYE05pVMho8lJarFr46cdlEojBTiBJasokpGTXQw3osFBitCy4gNdD KQ0Ev707t98LtOY6rlu9M7W1S9diIto5MYsRsRwGQaU6qCA/kvsoaa2PrBp4lRah H0lyV88rM6QIFWoQpqIC4sdiDCwhQsk372s32eTT2n/XebtJCtesV9eL9QNqYn6z wo1Xo9aUQ9dT8DOi1dcIcQsE8zqfIBG3kK+xKJFiAPKS4deUcRrvHtJgIB0gMjo= =fdML -----END PGP SIGNATURE-----