This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-statusnet-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 16:46:51 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 3499ec6f6b0b00c4fc7698b9314be0a490dc9656 * md5sum 76aba97e3b734ce81dd6eac98b056a80 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM7twAAoJEIXCXpWhbrlNtgAH/0wKuZmcUkgrdmrDJ9UPHlCq 9IRzatNLK9Z3Scephdg94i0ay/B3Mhc2VYpSWCpyJHFmyQv3aokolRHLx4LKcrsA ylD2s/DR0P8TN940+YiZ3GWIpUc3mk1qZKUJd+/eyi8oRVYNX/go8XWyxTuv9T9d dC6p63hcWzA1U4qy2hhPYjp37bf4m9334KgcXAGyl2p5x34XuJP8dmEtpJvOr+42 bsBdNpk7Nol5z3lgtx1JZ7LN0F3zGzuP5VlWnvbBfbSlJ0S3rzSRtMuGSNCYBzKS 6FpF4Y04odU4o3nCT4+JnlOjWuHWlpk1C4+B3a2v8vGcghWOluVNcxf9Q25+/kQ= =/Zbc -----END PGP SIGNATURE-----