This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 09:20:27 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 1e50dd8a9c0f147ae8471b5693b075eb864e9d76 * md5sum 37b4677733a8bd222206871764701c47 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc3JTAAoJEIXCXpWhbrlNd6EIAIpbp5qy+paBgdxxxonKd6Ak 8OxYaBt00so8ZidmamYfvwdFicK7Oo1e2EYk1GwNrr1PuPlGq/DvvWWhNCOGo7JW WEy0NoF4D/Yd0gRtWupAHNmNBePKrCC1S3MnoYL5L4ZuZ/Uw6WmQVmnW4ryH0uac buBBNs4lexgNBmGq64gxXkvV3GOaUdC7jZUFyAHHix/UHFzOswwvJWb3qrjvVmt5 lNCqo4CjjSVAT4R+yL9TP6pAhmJT+klNXeLGj4lRmlEiHDQ+zwVJOFIISs4lkKjN pSW1Q0Ra9dVsdnlqw4t6gb268BDJ0HGoXiWBzkw8yTgxGCW5DiNIW+eeojrNMQE= =DtCx -----END PGP SIGNATURE-----