This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phplist-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 23:03:12 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 87c51a3fd26272fa6531b68bffa5bfc5bfe3b0a0 * md5sum 8675e27b2bccb27961c76d65080eff74 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnIhAAoJEIXCXpWhbrlNYdQIAM8hR0Zr70vSLVTUKpgKl/vO 3Ow+maw2LWaye3FpPSPTDPVWsF5m/R6LHn7OvRcndvvkziwrntLKxMQ0K82F1ba2 UB2MchmWVymMREnTniuUvar3lUest+wBYH409r+vzdqHCNVvQQhpXCqmjJWpuCLS YF+Dd1rwn6AvsWZHzhahg2jdst0hFTHDniNZ3L8fkwT4v+p4N/h+9oSwPXjSQJob CeWxaancZq6XmznXwpPpYyBX7WkwvReGWohWQpNb+DMkYPD2fChdi2hVIvZ4F1Vs fpVintKNaYT60xWMro91lpLDN/P7hanZCet6GeQNedYQr3c1sURI0JkQ3V67vr0= =XWAX -----END PGP SIGNATURE-----