This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-typo3-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 12:38:46 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 232f97d05228248d0d8493892e1706278c6e8325 * md5sum 8688cae8e2d3a655f2aa9467a7778d58 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4FJAAoJEIXCXpWhbrlNY7QIALxF7AN/0EwZ0a0W6dHuWFgY pQFEdyh4xsLJ88kTszn0e3GaDD+KtMhtm6oCxK14I3w1Cd4D8a/cAfu0+dNmCZdn HyrTmiM0S8aq10JST4gB219QzzozsR+IedJQPGROFmGmCZQ4FWGPiFsrW4+4m8r9 jSb7sVdRJgL4ym0bvsgmwOob58ZYKPrrHENaHzyEQ4vm7UROmIAU1Leqy4+e77kH HGEzHnG1MF6VI9i4T+S1sdH1KNNlNegMdSWoOGLh/VPiA8sgt1tGMc9m0z4lYjU9 32UcYPNQMehYvuexfGGEYRVNsciHewKB2NRafp17cdhW5EsnJ0APD5Gd8ZN13Yk= =kOtW -----END PGP SIGNATURE-----