This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-elgg-13.0-wheezy-i386.iso.sig gpg: Signature made Mon Oct 14 17:30:22 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 3dc25462e896be93de46c4e9b26f044c3f784180 * md5sum 158a8b8959ce2fcf98e144ed3485e239 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXCojAAoJEIXCXpWhbrlN+L4IAJtthflMify2BWORnRWjrBC7 cibcgpdftrN35J3JYoInXO31T12K6aGSo83gig+RxWH3ZOI5YoBUvalnPzuseMct mZI0YfND8R/i56/iTp3pqdmpy9cv+16vQyn69pM3g5uQw3ogVX6qV7oCpdoaSejO jTBGBnjQl8Zsn3wU9pZLofKP7ZTP0N3XYIlz1sinGcM7YTD9c5sMmhn+xZChLyDt UFBwEMFTR6IiI/7JCvOUq4+CMWBkpvT1L6tZmG3jE0hZa59GzuHV2nhZ3CzarNn5 PsudsRERILak4QrFp6nKUy+PWvVq8Jr1PTruJJ8l3epABu5GhUUzFIJ1wbGZPyw= =AZ00 -----END PGP SIGNATURE-----