This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 15:23:37 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 159c14adacf3953646f67375218f49c762a811cd * md5sum 760aca948bfb131e58d6da6539b77b17 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXV3uAAoJEIXCXpWhbrlNA2YIAIDL2MMEwobZ/BdLwEV8zb5C iArjSfCsdk6UD3RRU/viKzEPN7/96J1myZnjTGqxLsxadx0jNrFLmklUuDnLBrmd pTp//j0WHuQbJE/KuL6jhvgbmSChSwO2hk1Yh+sODiU74MqSWeRgEhqK0zENC2wJ I2ieHxmWZQhUgDiWkp5BXVmoZiovJjcQxFeC7h99zVfyL8b0OnqfyogQIrT+PI+5 6zDY2pnQRAUVJLIQ2SnZ6ldAgA7k9NvlM1KUY6pR1yLLN9KMA8n+MpnP51uD+RO8 hN2D61/8maDPHZ5aH143i7DGvqj+3iowv6fZ58CXYDSVUWVWPJsMQQFdGTMxpdg= =szD8 -----END PGP SIGNATURE-----