This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 23:04:05 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8ec63a0a10dcd102a4c8c9110edce793f74c50ab * md5sum 440685dc24e3e05c3d10ae8c0f013658 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnJaAAoJEIXCXpWhbrlNO9oIAJB3Fuzc6j6v/YF6LFOsZPp7 e9wMp6ASPklS0daayf54x45FMSdj3BvaOF5duLXM+At1wHjPRIaQdC/cHbnFaial 9X+2EojociQB/VPnpJBfn7NcDifisj4mztIFUM4jIye1N/YAEQYqzsojGl0rMweF Geiq2VNs6IkxvBb+pJlaRvNaX7nX2KHBGCKIPd2GAXZ8cTeW8aF596wGHAhrFF2E 97mpANXD5jDpVz+6P57Pivy0Y+GpdO+P6ep/oOT93hvlhcFd1BjtC6iGFfawp/fG R30xC5LPS6V2uYGO/oQohE4bKvpin3FTVeUOQaA8bnQ93xasKfZ5Szo6UhjQ6ig= =/P64 -----END PGP SIGNATURE-----