This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-django_13.0-1_amd64.ova.sig gpg: Signature made Wed Oct 16 08:22:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d9361c4326eff96ef9d17488a7bea525b10b7f54 * md5sum dd136d34b27d2acffd12b5b2ffa11ae1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkyuAAoJEIXCXpWhbrlNkXkIANoQIFmX/8jE8U3kLqMmH7O1 KOiKxDge7PlGRXONVYCNyy4UHJShgzz3nBCtVLywtmBgnduSpDSq/4QAv/u7iysl GOozG1Myo6nmLOBlWXorWNmfjRCrf5ESBQ63pRD8K3F9jAcCht+S9Q3jPrUZNmkl tm+0bqRGtR2ATyL7pJkSczmQBcS+3Pj6/nH7ADQJRa55emyU6rjmMDyrOpCBL2IV WADyuuqtblqSiHqx5ok4dcG5SLJ+mEJjfgkW4NP/39Fl5INLGKf2WF9qTD95fpS6 b/hjUsYwfNSx+GnO4VB1DQg252wi7/4RvpcsGN0EnbflQhe7IGR3E4gg7tjnEkw= =4sUM -----END PGP SIGNATURE-----