This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-12.1-squeeze-amd64.iso.sig gpg: Signature made Wed May 1 12:54:28 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum a3ab8957c6987b2e78010328afb7813f1f605976 * md5sum 4047ffb48ffe8689d9abfae45a22dc27 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRgRB8AAoJEIXCXpWhbrlNjfYIALNGg6SGW4gVMcDMYwzV4Q8H QOVWquWkbAMSY39vqV95Nuhlvz3RbK56qMKYLROS8mC0NG8Xom72hif7tRRLNkGo opZTJF9N/mZCN/hffxIROwKCVz2VN73af0FYn38hw6UVSf3m9nBA7/jkD1Wex1MP QTo+jPtBlN1/rNJBnCHBGkLOhaLJKQRoYVJiwNLPT2eire5gZG8boE4PnubD+ckY Bj6ew2RFbJzTl6nne80RvEiU4ET8Z7wqwCO76iVqJ04fUC/KljRMpmhHntO6iiLy ey6Z4L3oYDQMfvHLXzuJnxl05qvykgCR0Ju3Bk25j/F3Gl9r8PkN0RhY1qSQz+E= =gfXl -----END PGP SIGNATURE-----