This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 20:27:20 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 832ba2450965f26e4d713823c69bf0040e76d63c * md5sum 21096d02b5788c3062368675402331f8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXaUeAAoJEIXCXpWhbrlN5IQH/RzYHvjG40+WMVPxjEgCtZlF ihlFLgyvzb2/Bxs63nJnAORBABbvSanFMIXsh1rsGEisWFlbqZBMNc9RyeBsZuqn FylOf2G5k2iAtgMza0ny+Yoy6WoeQloUKq0f9VLoOdP47keH3D1zxYjeFsKRQDdJ F0CpCy33AveHpvnWwAFSzeN2g6m2kbgmQkjJ9Cz3VN1r9xNTyOcbqL4nnlRglmJ6 Y5A0sXi+YUUm4piQwQVtLM99VsWXoSVSucZpTTVHaLMCqV3P5M6FrLe3SioPOeLy IE/LfifNipUBUeLTIKrQvTvqQRHW+ZG2kC6+8OnfTuNma2MWHZLyhiqmcubVdrA= =jTxN -----END PGP SIGNATURE-----