This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-domain-controller-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 13:00:15 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d74278c3ee1dec9e9ff67f89cdbc6d0560f9e9b7 * md5sum 40e4ac9b11152cb7750a9fdb648f8cf5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRreTUAAoJEIXCXpWhbrlNSxEH/jBJZF7l0W6K5UDSF5eosy0X lQtfrU8DI2egTSu0lBzP5vokscyVIOy5qXnaRXzVDYLkQ2iXU+C5afEG8fEMGOIg HDFrwRd+RpjFykYqpMPRKcRHAA2fc/bydgH3wIC8WtQCgDNO1yeEnvlC1K9gRX7z ZI/kRI3MdmJh88khArV0GyqmE1nGp5ubOBbRSspW7eKRAcdctAusB+4p7CtB9P7q tj2hhu46ZbVcf4CtZ5WuHHClkoRd2+u35B8U+SvP1Sk+GKtepz7xwtDOP+SlL4sX 564G6txIhbNzcY31DilnsfIuqZcTVbf7UGil9ohRuemheIuEGu0EOJvDq1rYIIQ= =EYKE -----END PGP SIGNATURE-----