This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 23:45:28 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ae46629b49730be2942572b6934eaeaf66b02ecb * md5sum 63ebdcb718530cf30c5c65c237d315f9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnwKAAoJEIXCXpWhbrlN/XoH/0zwdgL4vJJ4/Zcj/K9vXCYr 23dkLp5ljEVGECUpUOkV/6iTl8tqypPZEVkqcdJXvKkzuC/ubu4KU0fnYbU/XkKU lmN1B3O/E8UowONlAe4oLtu1FEFYB+I7px6PNfjJ3OfZmcBN+ET6crX3Wn6rffts k+fVJy8PNsD8qjBdNUNoyPPbwSzzguBLeoTEx+O3M2w1yM8BQFFwIbNHDTDf9BsS EaEAT2Vgbednl9niFD+9Ve5jXzuQ1KwD40sV6+b4sIskrh3KE2hIcRRoBPwHwqKc uYi0HD3bnr/XopGFxXvNiI5cr/Mb6Hs3rlA7P41oV1tMo+QnqC7KhontyDli578= =z5ii -----END PGP SIGNATURE-----