This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-python-13.0-wheezy-i386.iso.sig gpg: Signature made Mon Oct 14 17:12:26 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 4869a631253cd7829a0f253ac87614da45c0caca * md5sum 061b5c7c7a1d0e8b6139da0db3176e3b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXCXvAAoJEIXCXpWhbrlNhq8IAI9HsuBknL7wlj/qw0rc90V7 tcieavOffUXbeU4FYkkgl1gfOELwA2S35F+eNkotDpb15Rd6sdsyMFXz41WH03t9 +Gcf/XWTnN4ThwfJagamP5N00ianGzOhf1ouw3x8dEUBUA2DlrcvDreL1YMX0zsL DOOfvO7B1LdPwYEWNANpBRiYnbUDoooxUC1+iLqZnvcDjwKfvqIWO+EWakx6i1T1 D3dT5K1VpVmJ9Od4QVok9S2226ZR120WWJg41TcxJ0ESKZ5etzzy5hu0n19YhWhi N1hyEEUnJfzLXCv4WzwzkaY/i9L41i+vylqKCWo/KE2GD3S/63Bktmu16rks0rA= =Y7zk -----END PGP SIGNATURE-----