This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:25:33 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 9f106b0fce2e7a14753799325b3f13eefa71c210 * md5sum aacd710215b6efb6e3b0b80964e85aae You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM34wAAoJEIXCXpWhbrlNvb8IAL85XKXo/FM56dVz+UGlVeuc onkz7ZwN8oCpHVmyahbU6qC3hws6HCnsGQtboVMuv55sdMbiXWZsrb8bAMGJsFNW iiKQxRUQPjw8MJO6hK7B242EnTMHDkzttpbInNApupmyXty2iPS6pW5ccOuzS5uN xjzGayTSw224FJ6TznmDzIftVF7Db96ZTe0SX5Bh3W+GQrA6XnC+g+xGAnmMnD7W dewEFaAFJjeHSIORSPcdi0rOOziJlSmgbXhNgZd/VYKuOu34lPxcqZjOx1jN9rQY Yx2/RGxONmLuEOH/t8+Do7eWzYXws97DtIR5ceaqE2lwgE7sdu3FC5ptwD8SpBE= =rkz8 -----END PGP SIGNATURE-----