This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 16:51:44 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 306f022ad66c0aa62645715548e32ea114eaa47d * md5sum c1458305609c9b7047dcf0fced021641 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrhsXAAoJEIXCXpWhbrlNLlIIAOdS0H2HVsHdZKXDyufE3eOX 71wq7JZkV2ar63UsVe/5KufmJv4Zg8onCGCTgej2wz1Jxzyy4ImuXH1nYNhSa41A ntErxXQK3RqIMDTCMpA+/2uLKSZDIrnaROYsXYUrWnMPb0BnMxRo7HnPEu2NRjEg 3DMZk0xAX2hh6ZuqhM1utjg/t0sJLaiMeYutB3+xxeNkYXwDnljDbMA2F+juclX7 TsyiC7G5GUDuH0WpkJFHX65XCviVRpSOM28D9r0SoYaeIwb7j+N8UnO1D3uJ7bCG rL/jq2YCSx9UQs+EmB8OhUH0TWfZDAj7aolkje7WN6A5QhDpQ9bY/iWV9tMqdSw= =AYDL -----END PGP SIGNATURE-----