This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mambo-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 16:42:03 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9ff9abd8d4f6b1abaf2a97c632e1955325e0cdc2 * md5sum 3a1e0bddfa0c5290ba734f8dcdcea5bc You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXBRAAoJEIXCXpWhbrlNvaQH/00K7Uj9HSVy1mkTgZTxGk8u Sf2pG2A+EwYgQ7BRHDLI7xSGJ6/M5Yxpw8jEI9vzmKm+uA9+MV7dC7z1G13LDQYa 0X0XcdXH3H+NAHQdtM78qXz3kgs/AQgLmWzt/kkSPYjniQzfto4SXtbWK6wgFBrb d3j+9fmm/btn5oVFXVvznF3ZKOdIZQHruHqWpWUw0mdfQqt4JAfOtRKv8IvhHvMa Dcn5SLe4l5M1wNMwkE/3xmPPM1U6sZt57ebmQdTOngobZqxDATQ8ySKNn/zUxvVq xKjXuMySdkHTysjjKvz19sbyKYuUh4wlLPTQcwj5SGW+onnUIrAhqBY/RXqH87c= =kf7+ -----END PGP SIGNATURE-----