This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-owncloud-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 12:12:43 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 73734210a417c70f89bd8612853dbd4cf7f52127 * md5sum c827cdb0bed65dcff66750a445754ead You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3suAAoJEIXCXpWhbrlNWT8H/1Qu7Zmxpu4XVrwDrUKfGP0O yBg125jiIB4wgTnGSlOYIz/G4QthuEt4P+e6UQBB20fF9tnj9nmhvRMUgrKDK89A BAwoPfzbv/XRdlOY/842VvoLaGjCMU5vxYLcEBldepudM8F5tFbJKEtiIX0PZ6Fn JYLfGdfDGfDZv6zh4li/QJhTPBhmftui2dTphnRzeweYVmAwx/TV8nGmk7iIl/XX dmBGVLJhWd3pO2KZnJkTO25ji3z+HczaLMhqV+TgXoq8iz50nW/rBVFzcS5zA3h5 sTEUDdgBZRWOYD1jsbKDR8Vpak184g293fTg+7KiALFEk5+m7y4TMX78CwnZRT0= =Q0Wx -----END PGP SIGNATURE-----