This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-oscommerce-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 15:06:49 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 91a6c7b4a10e3905869cc6b7020ea4cd06b8b3a1 * md5sum bb5fcda61a1e8701ffa5b912793f23c1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrgKDAAoJEIXCXpWhbrlNVtMIAIEb1SQPlRsInPR9Q5wGfQ5Q A8oICpiUQlskQC0iIYd0U1eOa1C3JEnEEaglxWPBXA+3R5UyK/lREH2rwNSHAXS8 4NC9iNBz1izrk9KV259hXJQbMUHOWl1+vcWUbMKcSwkZchfYvNFsSN1YJZl/z6VK LsJaSk7mu02boTG11H8dEBaMKJM/dn30+NkRxTCha3jQXC4ZC1KqVwdJuG1NQ6J6 4zOlnotbDbNBo6Y6uZNYmpjgGJg6Bdm8/2p8QXsAx6OJlpuZmhJ3b1//0tGqinDG 0kIajRHJiPpiZqfp56wn2RLYoqo9s310G/3bOVvQe35cyL0fyM+xA2j6rzFbnYI= =dW/L -----END PGP SIGNATURE-----