This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-go-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:08:24 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f675873c651f25a2db8da43487a4b5917c7b7661 * md5sum cd6ed8a4321b58b45b149eea01e7179e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXklwAAoJEIXCXpWhbrlNyegH/20TYxNijjg2MABJeSQoXSZ7 TI/yCzQxadcTgBv/9BzKgVjaZ24B1SraRBVp/Iwqktqw1nCURRHmT2sMky9ZtJpj IB15Dm36DNxEU0QRn9Km4xqQSKSIVBWOj15HLpgbxniR0Td0fsmw9vKZ8PTkT3yY KWPkpLDkruFotXTJgQQpvTc1CcJ3CPgwPxyjN7gkaKYciC/H3BzrhoHspgP0hHD4 7dip/6VtrP5F0GDJzhSxwuTsgXn47huBjL44lThwzm/8FuZCGKx+Fxfk2iCvBtpa uTZ5mPnmJTUaxA0icTEA5NqMjKMHvCirz1xWNmeVbqr8vW138Dxv1iYJqOJNeiI= =ZrnD -----END PGP SIGNATURE-----