This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-13.0rc3-wheezy-amd64.iso.sig gpg: Signature made Fri Sep 13 08:13:07 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 2e73eb7091ba829cb922f9a37b5fa6ec8f75b8bb * md5sum cd145f0b7063dbcf0753e23c2d3b387f You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSMskNAAoJEIXCXpWhbrlNmi4H+wa2Um6mmRenIpF2U/ehAyOw SOxrSPt4PjlrSRd8w3P3t8/jZRV432VVuPTQcX3Rn7CNS2Z8K3YJdLao/HdF9L4T uSWZieCc5WK6Y4r5s9k4g34Mqrp6io4H0kkhV6HJ1wivWoY9+xIgzUw40cFzGGfU nbSSN8L511qt+flUPlekzqmKKHDuhOsJiFy/d1EvyqtBc1lX/GdKdTAbipwEZwvW PP+P+m/f1cAqB/t+h0CKMJFQo4afx50++BJ7MznfwQv6ZiRzHPhrfAkno8oi7icH 2Mydb6I3yCxPKiTiGPu5+0JEZB0D8o5FJ50YUuOfMLuCZPhvbzKbJG5NJqD+XDg= =+wse -----END PGP SIGNATURE-----