This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-tomatocart_12.1-1_i386.tar.gz.sig gpg: Signature made Wed Jun 5 00:32:51 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 823ce4f1f0b3ac9c74c99e090df3ab9cdffdc7e7 * md5sum 2a4d3ade6372a04d4f8d8c7c4e2dd554 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrocqAAoJEIXCXpWhbrlN/lYH/jWK05yMRzqB4nHTCs9WFgVD QHYRcJ7BewkK++ZRZVDsruzREjVsaj0hFd2Z9KCz3RkfmDykBWvg160l+xEWFVNT aoL18kP0894CRWCTHvNTboGVK9KKp6Vb3r8kihmQXUKorMGxm4QSwzIz5tG+0aqa qWgrzlOlpA7vIgPYz0DL9II8vTEBdAt+3dth9ejPkt68Ovm7Q6kKFJ/3Z+lHrwPa +z0ILPKX8w8K8QUCrUPRLHMPe+wLtrlKsITMs89AlLIfxofu1Ok799CuDjUwtNZ+ SdOKZlNRR7vdxbse8Paiv+PfV24jotVMkIpTdl3FmjhQHK7PWvdWz7WURJESCJQ= =SiVq -----END PGP SIGNATURE-----