This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-zencart-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 01:51:47 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 0057e73ed1bdaa3fe75c37f82089d4225c3a790d * md5sum 74caecb4ba391599842af2084ae4b105 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrpmnAAoJEIXCXpWhbrlN+wsH/0puebbOFjaWViarCZmqUQMe OBPKo8qVi5GjLKhuSWx9HQ0th41tJA8YrNnvoD9PYR45hQQdeh0Bx+QOUjF0eqQ8 tDqFFvddww09IPovZXcgnGDbebosycL9qOrVLYSJX0UdIryxo7r0nki1sUqm+KSI 1jLRovLLAO1K8B7Ik9kFxFIAeIwxcH0FF7fav+DQA8Qlxt/6EoXQh80AlsDjdCRD cXn9SFtF/hqAEnapjzj1c/NCyEa/WmYU9zleGEFn06b1gIlS6upOWuqRchN7BcYW CHLzI+7d8tErs7kh2jdfLroQfUfrbT4fQanGxbwBeqY6vT+jGm12cpz+WAg8yN8= =Q+kn -----END PGP SIGNATURE-----