This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sahana-eden-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 18:37:33 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 3534dc2f40ebd6497f9b8bdc1f6907c51d4e19d4 * md5sum fa0a5852b6d5a9ec1aabb9d9137af7fd You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXYtcAAoJEIXCXpWhbrlNikwIAIr7Uksx9qHo+dHUlXH0abUh elb1wjaBG+61XUFXgZS4aFIxs6+olrWkNbva6h3yNLhikDVN8u3fGP0NFfHbTr7O nyVRGkW49GNWA95Pl4oPtVXb469Fnaz3WsGXtvEmm+GaSs/h/7iOQ8yP+x45q2Nv Y9Udg6cQVHxlxdP6Fu4xRQS7lCHNclTiZW9M2/pJfm9m+OKiSU2UnH0RdS2I4Tnm uLwIOK38H+yQ0URtpFW97USntxsSkqGROUHTaUwuHoWJYbnB8zLvuAAPY/LzZ6yx fbAorlUacVzvr3JOoMKWD6u7qtz3jY7aC5x97z4+mFdI2fzqrZLr4z5yYLeJ+RU= =9A/2 -----END PGP SIGNATURE-----