This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-punbb-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 00:05:32 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum df606d610d01ae2a79c944cf9fc00a16443db348 * md5sum 147870c05ff6ac23d9354d9636fdb288 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRroDBAAoJEIXCXpWhbrlNcTQIAIFdqfE2Aa1AK4ZNiiHldygj KgoeGdRq0D9sllB1pZgEOyCFu6M744vrUYYGA8wgjnxJStjveq5lueDGRgn9/ZEb QnPo/8cmWMbMFgA0Pk+vhoLTBo1ZcBE81jqSTjRmKbBuPexJLSINpsILNES2iNhb yMQz9eIxy8SyFNg9zcrOYwCr8G9lDmaD9IbZWQ4vSMzTON1wMwfpczlUrmpJEmio Cch5ZkHxF2tfV4CBGfFhrwndMRFdO7H5bvn4KiZA38mqRro//RyeFTtmvThP7ag4 N+EiE0SwJqvF653+y3euSR326q9HqK0caoxYTuhO+zXmZs38ceLK1WTmi56uOFY= =uXeU -----END PGP SIGNATURE-----