This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mibew-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 21:57:38 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 27e810c729fd776c81b76324e099354057d214ee * md5sum 7b48d0bce9dc33669cd6f10d3c357383 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmLEAAoJEIXCXpWhbrlNzj0H/iKnjXkm+T35QclAiN6gSoXF W9KjsCrWx7XFvsTPf0d+HND89PSZYbFmoD+vqo+tbWH5UsmwL9VtE8LY3h9I5HSp FhnRpV91ueqncxWaK9vxIs/RbILCkLwU1yKp1XGP52Hhw5M1EmQjm8trPVTKApB5 mDgo9A1e+RrcXeaYYFgWaGWQuj6HyUWoce6b2L0Pc+CAC/QwhYdDns2877zUh/FB d1SwusqRc4HjbOkl1fyv5BbEvM8sOjkA93aZ+1I+agGSJyT5fbHpkFDGRfmj3C45 oh3Wev5dBfAMzjlZfQAlagODT7R++edMwYC2/3Seom38l0yK49gn/iqBJZvYU8c= =IpDo -----END PGP SIGNATURE-----