This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 08:26:44 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 183451ea8f37e48a00e8b8cc3ec96893cbeb018d * md5sum 806ff9213250fe5953fb6c8590291a15 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXk27AAoJEIXCXpWhbrlNDAcH/0dnXqfn6UatLAxpdApIq4UY 8ohS2sTjk/fP/WimgiRMCv5/B44RvIaeEi/A/hdZ8xKhqqdQmbVgQHsuL5qnMTg2 LSs03j0D6IDL1FXJPpoLZd0JXpC9/W1faePeEjcQLwuXYnzzqoF/iH0pJt1zxym1 W8pfYoGVCPT201GNQxzBtUtUnCmkUoFIanU2ddlWwXNQw40zoZ/GzIcrQUJIwWBC /2rdH93Nk2Z85++jTkWvkjocKgbZA3dKVOxyHn+n1QmqxEXgEI0D0OSw1is4bu5u PWzhdpen3WjvJwu41ci45irtv+zmx0FU9ryWEMxbCe1niMo+EEuFpdWF05XFY8Q= =PnV5 -----END PGP SIGNATURE-----