This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-clipbucket-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 08:13:31 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 060282a4b114db884a256992930f272f612efdf8 * md5sum 57b3d846b5a594f25ee7f0376f352023 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkqgAAoJEIXCXpWhbrlNh7cH/3IIhZ5mbe/43ndyhj3L2oJ8 nrx+uGQrBWWP1HmUOIVe73k/3y88PYlGi8fjf0uCoJoGLwAe/ycyu7Gy5dQA1u1Y r9vNqQNkn8lUVXBeigNSx7xSZ1TWhPN52ND9iEyQckcny222/gSu/8UDms8Lj5Ke KXT+1MUmpxM875f+kHEsWY/VD+UX0tTZ3QrYfqRtmsyx9YMYoDIz7MgULrp1/o4B bRv77exn6r+e+l/jDrdJQg073A9Q0XeQ3p7IkCr9qZJH1v8sdORhlgfbaM/K9po+ 4R5W1cppBEnGqRgKpU55413StCNmDV+5Y+9qQLhsjebLrfRRq1w9xC3gTz2BgzQ= =gGBW -----END PGP SIGNATURE-----