This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-jenkins-12.0-squeeze-x86-xen.tar.bz2.sig gpg: Signature made Tue Aug 21 15:45:15 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum abdaad6be3d028753e8292a9208d967260ea0f38 * md5sum 6365d169299abb3b6a4ca0ea9fd82831 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM6z8AAoJEIXCXpWhbrlNf20H/2PlTqvF0nhVrnVZoO725pBl FD/kRXULssfwyqt4pxL2F6rMgL3oGE3qgsGdVkMxpJ0ANsPXHZpQDnPmBlr1ldfP fb++EgOj1DWT5NYvb7TGiTgtCXxopiuk1zg4aojLefpoBPOW0wjMxyr+EM09ekz2 gHOntOVYYAr95lPK4LncfniX8G62oeG66h1yJDaJP+H4AR13o9EOrfpFgnQ4GC0E 0ceF8ZM2M6uAlUj16BFwTmhdXK2Q8kfk1hxyus2qtk2gpqelaRBKwFH5k28c36VL uFialBrl6yNnPt36uxV+Ma27RT5qTTtnigJ09yaHpL2TNYdlJs1N/8Wti9hbPS8= =0t5t -----END PGP SIGNATURE-----