This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-couchdb-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:11:26 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5aa9841b7fd0004d26900ceacd1032e3464648e4 * md5sum c2376433b4ab1305ad9785cd8ac6abf8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkokAAoJEIXCXpWhbrlNyhQIAItgRfnZbQHMMdKWbZ4qhbwm WZI8ncxKQIsJdUP4mNko0NyKgJv3KLwpenolmb02bdyBrzjvbDw9k+sGpUPZkLsv iEa4oqNoxdGheOe3JkHjUnKV5lkk13koWZm9HZhU5q4iZfZ/aIlT32LQGqvWsS49 x/1tqfQVQoIP8jqSKxPCHDQHVw5hUAxTEUmPU34ASUxaRRKug+5uv6b/OQg4d9GC E1F32CP//b4tvXqM5kAU4LOT480PX5NpPpSo8X7q8OuAf0jB+hrKl2Ro8nz+rfBf EO++kDi3vY5L4uvN1nly1kc28dO/yl5SfzoAk7Ykj5z0CuszGF5T1qbMNuECJ4U= =z166 -----END PGP SIGNATURE-----