This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-nginx-php-fastcgi-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 09:35:47 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum bca2d7e283a790fa755b68b292e2eebde8e1cdbe * md5sum 60b594540ff8a26cbd1e150f3b1dab22 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXl3rAAoJEIXCXpWhbrlN1UwH/1mqZYcIf+vnBD5Huz7Y6Qbe NPA3qMazxl1MhWreM6B5am78Zb3OsqOfJTEVBgYwjJr5JcQyblY0i2tQVrfO/mvb 7EFiU/ITZWXwWAJqbd7Kdv+8SrVKNzxkq7obkpb10vAuaO/cvv3chj8FA42l1E6W WJ2wO5Y1zj1NSEWo2CN3xICJluZ16Nd3NOuxG/rY45jTJ8GYKx0UM+PME1SE0Jhu +pY9PdY/r+4sWppigHcfTMqjnU/uGjAbdGrAsnoWFh/pG/Sbxb6tZkICN+7naENx YB0arkN0mK5YuihAgHxrKPb6Dqp0pAzmjHf2s7QyA7Jlmm5IIv8imGbgNRsQ59A= =ZtTH -----END PGP SIGNATURE-----