This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomatocart-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 16:36:46 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum f746edc739cb10b71c3d33d846c7ba625cdeaf58 * md5sum 88e3ff70244ea7311da560cee26e942b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM7kTAAoJEIXCXpWhbrlNhtQIALw6NyomyCvFay/G1E2d5JZq 8PB6YdZiW4uUKWKdzda0+VZxBuwmxIM/rYJWLXVdVay1qNwHdgPBZkS2JSilpndl bcT6WYa20tUonMOL5KkxBi9gKQT0K3+O2+KyCeScdbJPw0DEy8vFGkV3aVI0G9G1 yv0Fik7lbcNywJVAXMUYxhvCPikEXwDps27eyNKmou1VC9xfA9DeZUZsBUQWnX6K wdlfDwKzwSOmu4AkM9IdSCtAMxob31m8U5c0FPG6A+4iogJVXAuvOK5wpZTKUhBI 6MQrV04DfJgqH3AqnpQk1n9IQuE/6GkZedN+mpoLVwz1Cosv7mBgQ3LueQ1ILIw= =Mgg/ -----END PGP SIGNATURE-----