This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-jenkins_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 16:24:20 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 60d0a4212d052df95ec6603480b85209fa615218 * md5sum f9f3165e64faa6b7cfdd194b403d72d5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWwmAAoJEIXCXpWhbrlNQNwH/2bLlGy3iuR6xbFf9ZJh/bqN 3XvjCcOU9DkZF9ZIt4ZuSEzFku/ul5PUNeu76OhvXkjQF9VRjDsuSoNsRY+uXj5c P37fDdwK0qamvkrH/z5fALhYv7Jv6sjwr+BzIDYDY/1u7Z3Oq2XYAWcrloBk0CqN FZfrQUAZekJcECZZty6BsjZ2bKOlM0cYSKegK5nxM1uQdGp5gAp4wBTT6avNmgiX O4N+dR6uRr2BliPc1zaeL6Bg9gBAk/QG2/rif4s2O9mbjmSN+eFE96zWo6M3W+CL GURGVEEl5TuQjCGDY6vDxI1+mc7bAK/DQ8NRIPMjFoyxTNA3xpc17MB8zwd3R0w= =Tigp -----END PGP SIGNATURE-----