This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-typo3-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 01:30:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 32f9e6d8bb73ad576e23f0b1404ad44c9586b798 * md5sum 8d5c471bf950bcf07cf59426cdc2dd63 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrpSXAAoJEIXCXpWhbrlN0WUH/j4xbbr+FovtnmFHdeum6fWD 5IX6w8wonhSz5QPO1pN3QVEOAaWxQ0e1CCguSOHUcVaji8uyis4XRc99X2BkSUvb 4IdTqM8zyJJVaW/2JFVYV5lw1PIzlQjCzSmEURaHmHuqesPtO8esis/EFJPomSJP 2P1gekVaOBWw/2LdXGRh7lnkorQVfQiCLv+0MlYBIiMHcaiEjI2plpCu1nr03WHc cz8wN5cRfHd3WShPpbEVMmECDU3tRVlBVv/A5xwsyaXQppZhnD0fK2/bex8WA3Dv m7Ns4TGBzVkzDuP1zGZgPWK6kvASHHM5y2aXNcL1IPYORLmR9zdH+zTOqP9U1Vk= =+5fP -----END PGP SIGNATURE-----