This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 09:28:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d5b5d144974c713164515a40e664ed3ea5414aa3 * md5sum e5d74b32a6cf0fdfbf262c15540ff0e9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlwpAAoJEIXCXpWhbrlNk6MH/1gnaSztSeYjMeHk6f5TgIAk iw89YjSVBR76jhnzUIydUMEpD3ykmv06aGTr6Vu+1lNT+HRisjOndHCQrDe1ZByr a8x+ZvbjH9qj0znZSMwWRMF8PDs0RbWg/IuXPQ1Ct5iwSo/GaUOjdPwg5W0gE3Lt 5+0r46ciA1rd+GBIDND1hrZ1zjdMJTfBjP/v+pgSW9pHIdIBk4Fgpwrm5kaKHGj9 gku1UVxa5+p4WtRP3NhD8539WhbKBt5hW7OkgmfH50TusqbiQP5fsaJ+4jsBUYl2 jC3LbzKfdeQuC2awz7KCvA1HecoinkIbGjvOnALGaLWJLsCMRlbUJCc7CBvIzqo= =ZFFB -----END PGP SIGNATURE-----