This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 00:15:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 69d7cb8fe405e6cef1eb1aa71627e964c04bd2d5 * md5sum 65c5a4bda1e0d457247318e0dd852255 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRroMIAAoJEIXCXpWhbrlN7GYH/27e2KNcsnN56n6l/4Oc6rPA IBsg3z5Ecy0G9FtUldOlDg/luPPnBLGQkpZ4mj4Fca+5SnG9balMYyAXOngaOVwu 0x19wfI28sZWgkmq3DazlfmAg3kbB6LuVk+9aGaP6OasHyDnoMYvs24r2puWzISs fffMXhPgkIaLg9mHCaRINCNWGHXSwiCeCebzM1LQD/zy16k8lWITcLuGgLgBvItg 8SJFgIG03anNSEQue3MHUsRaXrTwBfP8d1NrAL2D02latxnhGa+bvixbMC8pm94X /nM4eA+sJD3QT7TI7qNl1oG0Tslo3lGORz9ix/zFZ3ViJTcgbnXLfkn0ox+KriU= =Xj31 -----END PGP SIGNATURE-----