This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 15:44:24 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 212f4ddc8650baae532877c1f23c4a1cc1940331 * md5sum 7ac1cc0c408ed5f10757e5b94c4d2eb5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrgtLAAoJEIXCXpWhbrlNUgUH/0lQMHRuM6azZ0kUTv0KQUBS QtN7t1cyPBX6VCYhX547rpRgh9RI8mLaVz0j1D9ZOB3lb0A884ZbDhHMtjsLX62/ yOnn6OP9+DlJThvKrAFKh/hNrbwzkbQhY4AlNoBwfuBUacEXVAUapOAGV9ypYX7h qHoZRZeXzAjZBep9PoML6LVxKgBE/dj05zJOi1zfauUZAkaKYBjR4YUZcAmqDuJK iotIviILpQNrWBYDE1GH8Uf6OhC9Gd1sJKZMMEje1ulqrWEDzzyTEJL4O98Jk6wD Ox5/iWqlYDhkKBohaP0VpzoJWMqvmAoNw3Y7ta23FTEnCiSjHdAWrFKuGacGhYs= =FDyO -----END PGP SIGNATURE-----