This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-zurmo-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 10:59:12 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 964574dc102001cdef483919f0068e67422babf7 * md5sum 2a83ffff2eda227e4f8568322131aaed You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXnF3AAoJEIXCXpWhbrlNO30IAJ8lad927F+iUE5CxAGwMwOV 8uWMdyboEV6A+aBABKVEcyizV7/365iz4Hda0YEqUYwT+8xV1ElOWJIvkxko0sV+ mWtbFmuyGBAJsffRoDTuS1SK/2LokQ5wAuN0ZzbmarrsDU12U0XS61+T6FDiJbUt fSYRBM3uOkbfNu3qw3HeEzKbqpylbVJLTKgovKPdre5rt1w2tV/DqbDN4NxR+39i ruMktxM9ZFch3ePIH3DndXd8jVpS27dr+ZHEN/nEUbTXz3A+kliFujfqzZ/0faxj zh4lhvLS+S/4yuVQs7rXCwTYzhPDtJ9lXKCUKSbhNb2LcRUMJU83Mtsk7o4k16U= =Vg8Q -----END PGP SIGNATURE-----