This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-go-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 19:43:24 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b43f99c9df85b4c7af1da00982817e43d8cb46f3 * md5sum 4369f774ab24d9bb6981d78c74dbf6f7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkNPAAoJEIXCXpWhbrlNUJ4IAOzjntegWfEEWHhkwmUhwI4A w4yRWxritl7r8JJDMwPZJr8Mrf7HsWauYGkc1NcxzBj718ChpVcoTecYi2HgnlYq gP5S3IhKLKPYkPc3VRaKWtIkBvH9ZhjQyPm1zak0VnQDcU5KfR8lC3LsynIE5J1m mJP29Gin4hVy+cBqA8XzBxgt7unQQaq3K9RZpBBv9TtcXA8xNvaFgzTtSElBR9so 4xbH4/WYkVRSP5CDSEhSm1L5zH/CZF38KcICv75EubCKkLum+fPPDpmHuy+efKZt 6ttZ9CJknS1n+26TIxqo0FNvwIgVsOcYJIa2jQVYp6LyFZYNs/444nXews9hGek= =T/kk -----END PGP SIGNATURE-----