This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-appengine-go_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 14:55:12 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 47a5aaebb446bcb05a601266b4581022095121c3 * md5sum 0b45ead662347bc19b33c11d45e892d9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXVdKAAoJEIXCXpWhbrlNVMwH/RN5PBq8zDKCXqtdLfkwG73Q p8iCJ7QW1EBxymcCzmb+4KvkdGwKQ0puOy0Jk5moWo9V75mobgGPnmtmZSV2I9Vp NzI3UZS5NX4YglKdWFR5xtz0QGauAkSe4HL2HP0Qmo+kjbPxZ9Jh3pCr0+QQEwpf FcddugQMtSwWfKgF4W5Xj6YJzZOZwyajb5+HyRfqvfTv1d0SdGGQKrurYpagaHLX yMR94SYl2vzNFqWrTZVukBwiF6ngCdvbran1NZ+8aPF6TniNda0IPLAhkWUX3ue6 gPEbQHYvnBKzvrDPG2EkK18691RZMZDrTQRCD7pk/4EgyamO5dEsn2Qj+xpoF4Y= =lspk -----END PGP SIGNATURE-----