This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 16:51:35 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ef27d3fe686405daad7848f019522f9254767533 * md5sum 9771fd858bcf2cddad9900cafa8067e0 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrhsOAAoJEIXCXpWhbrlN4zsIAILlYX+bpH36XhJQgFOjOz5R E9YBi/RepZWNnkUssDCDFcKvVs/V3tjMdrKJ/8bNHTuF1FuDrIqLtjFplOcR2IGq qMTXJrUEpgYNOsVTenY0fhrhFv1V8PQQRYzuJK74f9cNtMn564ezKPU5Z0FMhWei tgD240JpTdQLpgP6wxmb4ydt4zTpZu9i7msHj7s4fLlNhSilkKHtEqQAYxmT8suA OfmddHueoKWJX2orqmm7k5hQeldo7TL0sFDOT5Ydi6EaEl+5VQsOgQ0ewtCtPnGf Fbrg4k0uHOudIeXt9SyAi6UbKxj4JycKiPexDGBVmIx59f2dNZz59BflkwQDDts= =/U22 -----END PGP SIGNATURE-----