This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-codeigniter-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 12:47:43 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c59018f64e9552fb353e6c60eb757fdfb5be3026 * md5sum 676808d29fd5269b121d7002796a2bc3 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRreHlAAoJEIXCXpWhbrlNIgMIAJyTtn0/WZCw5mzeQB3dQaLa dpHISKNtsG8/mWxyS4WAheNN/xNGq1MZbD1+oaD0Ead3fEktBdjWYkNSYE0NCYrI 0ru62JCyrQmbBtInVKEn/yMByxbbgIdVscJv8kYcv6+2oLTOZpfhSefAJ3jNL3Ju zKnTqYq0EgHiRxgbY3gbbrh8j8kCTfPxY+f8zKVTRcC8O760XGXbzPmYjVe5+EKs 1Hz4ebhIGriJLq18TEXdna+aSnS/8Of1DYsioEnGTaY6KNFp9fB1gXyovPsmrVWz 1xnOr2/V1a82IHZPehpDwWq7soIHsjr6sFKAgIqppaBGcnxNp7TMHVRk4JfM9vg= =Iuif -----END PGP SIGNATURE-----