This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-clipbucket-12.1-squeeze-i386-openstack.tar.gz.sig gpg: Signature made Tue Jun 4 20:23:31 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ad4b5ae858e7c0fd0b04f2bc286e77e0b2984cb9 * md5sum 5a9b923fafe57d5701e17122e853ec59 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrky0AAoJEIXCXpWhbrlNVpUIAMqmjSQ30eXKlaK8lNxMyXn+ j5Nlzf0PHUFL19GPdFIO08SljnbokK5Vj3nJ866b2BDYnmthudL42B9QIz7YZWd3 612FVbS2StqQGTnsqvxGhBAc86m1ljgCq/sTaa+nB7pm/Y9LBy0lJsbwe2TNNVkw 3vv/Nrhqf3JG/8U3Yw4nAoGOnGPnLcre3eTFZJl4BxOBAkducTP32OYdppm3s3Jd QZQn+WPT5XsZIsHoJNm+vRj5thv5f6zLeUhrMqd2tEypv2Ss33O1536bJNEDTh72 fLfB/gatJx/yJvwOVPt8MzOuWYwLOSbLcB4OrFUdhlq5To77HUYKRGapRdt9Ntk= =3wyf -----END PGP SIGNATURE-----