This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-nodejs-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 17:11:10 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e38285edde8d1a73874f169d159b23e3230d9a20 * md5sum 9d93dab488afddf4b5209656168c37de You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXcjAAoJEIXCXpWhbrlN6t0IAKEJFNOXS9Z97Xn33FuS8g5Q 2rdMvs7GSNd/JwmfLy7Wmd5zKajbG9eh+WNWoFsPIZG/LaGslML2ACOtkZ7jD3zW d6qocUxh9Al2KuwoPYcJM5cqLqEHfGD2wBV7DPNwbGo+JfXJ85nOlCdYdhZ81QRL C9XfP9KpA4nF6GuDlabVQyoCJ9QFzWGa9vVKhgh3Zyq1pXeXzovBmMYR6CP9SMAl rkKCAqixVYL9VeauKQ+2NyWrFYw6AB1wiBTIE+El7I9e/02SSe2fC2Q/KbBNQBMJ cjWcvFl4rOCF0q5JQE75WvAv0ATItPicKiZ3qTgff6hG5mmLaHomb/QPE4oY0Wk= =rfIS -----END PGP SIGNATURE-----