This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phreedom-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 09:42:26 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 517d77e9cfbf7388a68921681223cfb68a03de42 * md5sum 85f0560ed32d39e10a75d1fb4d9b237d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXl94AAoJEIXCXpWhbrlNWfoH/0f+F75VrWB/A+MWno5mX1Li UsMsMjv7uSEe+fSex276G2NLjA/VGL0+JiiAJ+0KBs20f5bOFIjDFY8y0wwruOQn Ll2CRyh2mBE1CPIGUWwBd+fMWe5H+VNtBe5QoOd9cqQcDCH/gTU5IDzyUJ5dDAdW H8b1kj7GWQzAO0n9GZro7z7buT/5CoaxM3yypgWUZt2kTkT17PNmvJME2h1+kNfD VXC3m5om9YEha8jX1azwj5OIsZfUxQ9r5UYrW1yREYmTx4rNUr8iyIhJ9ohEJs1n iEEetncTRnoScj1+UW5xwBul3nfvJ7ZkAHup44mQWoZCK5mx+ACY8C36MqbsJQs= =J+hE -----END PGP SIGNATURE-----