This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-moodle_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 17:09:00 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 272d6e79b5e27699f4ea38052bdd2fb79dc83e42 * md5sum 314dc3583ed8c8a5fbf77d14a30c2af6 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXajAAoJEIXCXpWhbrlNfYoIALFj8tyb39gdipXxBnYK7Fcx F7kP08d9c4ZMI5iu8zj3qDCeb68ShC2ZWVZI1JlcVcTOE8p/ZuYDezC56XEuxVbE Lq4W0omobgmjaWC0Q/7VJoE2+BWc0I36/hrxxf3YXPNyTS5ov7mOSstPL6CgFkCv Jd9obkntDAHpoALq/owkCHplJvJLFPkyIgHDU/wWs5vVb5N73cAopo8rVRiQJ+fA tAi6P7qorDaNZevC5dWFWJi8X4iIm034lpVIhWynJ9+7FvO0sa5k9abM1J+SlpJ9 t0H/7LdinalRWfYHxszBIH5vwim+1uwPq6EAZmeR1ui5Ow4ZuhUOI+Cf2I7Nf7Q= =l81D -----END PGP SIGNATURE-----