This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-typo3-12.0-squeeze-x86.iso.sig gpg: Signature made Sat Aug 18 18:47:25 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 7a7fabb5ce38124607129b040db535c9266e130a * md5sum 0ac53e64e45c08293b18f946784551ec You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQL+MyAAoJEIXCXpWhbrlNZY4H/ik/PRdifW1KpC2j71Pf8Orh dsGBCNn2RItwO1rrF/zvoL2XN8cdWzEVBCXkeHuaEME9JmleVUIIOl6sv3fJxwtG yL651DSe+eGSlvEW9oBS8S+MxAnB78pkDgM7En5W9HBuZF6oCyVPmflTIRLx9yNY /vGNklCRQwXzEz26PSmRiNzjSj3n5898plAfsoWJyV8eoxPCStrYobLSRXIpr13+ PBccOGTdaFQiJiNsFtuGa77la+DmPkHtGYKrCCQOQEp/dv+7Dhk+NKVes83Jfo/J FiQLFgJ+Uxye/wxoffhec+5XytlfuVRYmlhp+NS8gQ6XVT/lRNaTD9EkkM/qR6g= =QX3r -----END PGP SIGNATURE-----