This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-vanilla-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 20:34:28 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c129ede8941f462120f3758a828bb6ca7f5be9fb * md5sum 6a02f2e6dc8e73606b424adb1d4e4e97 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXabKAAoJEIXCXpWhbrlNnW8IAMsTrZPCl8mPO84aDXOSPlDy U+29BP8h0FekBZ7stHBfzKpQPNmXC2ozt9jU9bVmLuVv2oR7cTrCLsnIQMIiiNKr 4aye7iXWjp2itE3ZZ0uUyU/N4wYxkO5P+20sMUiIKn2tllMRdcMBCX0de9XOrxV0 RBNvsJDsyZipTZK0Nq+BoxVqsPTCtYForzLz0bgihOy3csSorIWGXOb82bh97V84 R5HXD89U0hdVREL+chveIveC3AlBS+WQJPbx1B4VwFslLnP5fbAc1GakXZRuWiG6 wf4NYpDwHFqgIhN/IijRt4PDehUBCrUFaznJNteWg7kaj1aFT8LfwGDRst1tpQA= =nhoe -----END PGP SIGNATURE-----