This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-movabletype-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 22:25:08 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum eabe65d710e95111844486ea06f1a1a08cae6870 * md5sum 472883288f9044e5235a0021a2db8d85 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmk1AAoJEIXCXpWhbrlNeAkH/jp1QFnZQJ764hHVx2zhxQCq Sb/f+4wYs7UQpgVPFsUD/2wBca0Cb/O4Y38SWj0SRCZq8/paCVeytymzuK3x/gDI 1YwoALwTzKgCeClwKxvosKBC20uEmYtZKe1y6jsoDzh4l1inU5nViE2jVWbolAaf aoNHhQu4HLgJM+TBQMxQeEvFDaYRePJr80ZBq2bo++OpnjTyjrRuxWvJZFoyPxWq Fc5qzqv4N1D3ffVGlMhGjb2TTRcOlrIvMIOYhtkU4BLxPvSvxKA3lzeYroOTllPV WpcqE+ajKTklWAxJjSwYnwCSSkeh+varaUoolOSmI/+s6tCoeSF3oZywP6MQBzo= =7BDt -----END PGP SIGNATURE-----