This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 19:44:37 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c17a32737f13f95318ea10c0f41b7bb25d195a5f * md5sum 3865233543ac201f1686c84a6916f1a7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkOYAAoJEIXCXpWhbrlNikAIAIVJFRamHk6p01DQTPAtPMsj KPT/KudYhkRnzUB9x7pWPTrI1MF/A0twvkUPSlh8UBnoL2Wi9Ci5PDIJRDJ53M1A HxmzKykx1mjwc6GBfGBWS5qOogcQWE+CHAH4dCTAvETxY3oNMuEiS0Un310uAMBJ a+htFjXX59TlnGfEhRv2cZhOh+4JM902Ag7DQNh4/cD7ke5isESjJs+fhXCbTMe2 EMlp6lWqy8sZqRTitzqY73eRHY620IgCAqxiiGKJiNUEc1t4jKuCakkwYjCskVDV 722XzSy6qp7zO9YlCNlKCPGDrrTuiwEc+URBsQtRyzPzpGztSzI5nSNZ6jDQWfQ= =9wgQ -----END PGP SIGNATURE-----