This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sahana-eden-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 18:37:16 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum a09439a5438e64b2f5eb5fafb8bc1f2f136be223 * md5sum 45a774efad58c69c32cc6a19bb3d295b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXYtOAAoJEIXCXpWhbrlNFlgIAJ265DoQWT3SsB8PXYZWYaoY YXk5SqtU/Lmcbt2yTPjESwACUlGQMuVqFtuDZiISD/EiFvX3iLEOJQIX8zVFWZ9t zET27hAn9SvGCeNdmAk4i1kQTCo0/mRJOOexy/kuAgQcwVMFFhdo/K/zFA7lnYwi b1cfljJYlzM0O5XzApBUI15R9SokaX6uEuL+CpTjCYc1EOFb/Vaj2UfRIHPTjbWS fzBkn71ACBOVUsgw/ILzFLuMz7MdQyVygc4gwqJMEnhQfmQhOtz2elfqJ9Lf8Ngd oyJhKVj8q7cCTY2fz9yetQcW7afvWKqkG5cVlRS8yrMsr/OuLLbd5j2RYGtmSJo= =m2aZ -----END PGP SIGNATURE-----