This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-13.0rc3-wheezy-amd64.iso.sig gpg: Signature made Fri Sep 13 08:47:48 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5c98202ec1aa92e7d25e91c117416d83663587eb * md5sum 383f762b6d6cfce2ba751f51b7f75fb5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSMtEsAAoJEIXCXpWhbrlNiaEH/jkReVxYSoIrCnVy8rjx9IbH yKSxWwT0n/7TzOepQG40I28zH8Zcv2v7lFPI8qqMYSvdB1amUqqwL7Gswhu2UJaq UJVato/WNfc8RSW5jCsEHZ8PqmhQ/IXSEZWab3iDsGBJQe0YanwK+okBqnIrHmJJ NYfrDEwfe+A/LWjW6/Lp6cQT2kJx1N9yc7eCwkLKMwr/p09jHThE1qPeswBjPPvb CED/NKq0AXKyhucbRbGkpXbkHAIotpqAsQdXmHMzTQrf9b3tnIUPk/r2Zfm2eCmB 3r6Hu2ETecKOif4OEwTXL0NWmX2YfM2avuN1krKeakTof4ukgvY8t8q2GRK5ZiY= =+lct -----END PGP SIGNATURE-----