This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 23:58:18 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 4d852ae865c7c96e30441a8728dcf44764d41e39 * md5sum 10fdb6dc6f63cd84ca4e8e27d098ab90 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrn8PAAoJEIXCXpWhbrlNDwsH/i3sTdyZ99HtS71JbZaGJxeU WHxizCEOzOjuatp1VaZvl4e3qdiGvDCiePLSeMviQrKEb+rK9CSGmtdJjqQ82nTe P5aYNCNT5X0pnZt9/XI+5dExseDR6CragrOsxYYFHyYM1vnU+OgLczkncZryFZtv DGgwR5BH1pSuMi1wOQ2BOO2wo/X0q33Hz9lTXjOdMD4Fx02g6xzAMRe0242vvGwZ iv99ysovhlfhVy1WsD40il+pJ6Em34wzDCmNNx6V3xUuTC6owO9Ohs8Iyl7YGN3Q XWI7EtUA6p8Cy6r3wyFc2O3V9Gwy66P53SsRJq/d60K4gfQVptb778CFTHpxj0o= =Rtx8 -----END PGP SIGNATURE-----