This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 12:23:48 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 6a09dd58324e36c65fefee7118d22d2a0983ed00 * md5sum 9b75d4a21c2ce6827366fd664dc989ba You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrdxKAAoJEIXCXpWhbrlNFkwH/3NELqFEH6e7Lnr6YG/BdRlO 9/IRHPn/u0d/NAHZGzpygQ7Va74W54FRF8u7AGDLRis84i7KmhOXcaC1KGoSCboB BHqfLH4lYtNiGjbi5N7AiLGCeHsBfod6jX66iFeBN35+y0z+7R/B+RNqlaOjimE8 A7Z96FZ0bLuIOlzbZmTbVq4FMquFrEEOjvUySVDqu0bMhnhAHzGrpKj0Rr7bs9lW 0aSoZLMKxzLf96xxUvVNGQFZfDFiR4rpEm5Xx4PJqHHLNLpEt0LzJTHN8CcFTkK8 m7EJKXc8KIRrKC6n9eDzFa+fFpBA1/MhehfXZFIyLjsJgsFVvoBE3rFMuH7DI5c= =B4rn -----END PGP SIGNATURE-----