This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-collabtive-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 20:40:53 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5411b95cfddf0302dfbf9186525632460727dec5 * md5sum 662d4350f66593a626287959ac9566db You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrlDKAAoJEIXCXpWhbrlNaiUIALLf/QboF7xNJq3nz+b3G+Sa m6XMBJT6PYgabMSSw6oD+fPcIEoO89ssrT+844rg7qX8+k+azxI5ipZ3SSxmG9iz 5T77b9bv0wB40JqoU9GJfkw2NgMRUmo0kTIWXv5jZ5Lot8W7SE0EpvtXqjOWH05p 0P1e0JvhH/jbTGs2DhE/+X2pngrOH1m2y6M0SL/vzAkU+aiyx8tAlrF9RgAI3swZ wCOorsdJASBw3yF/UEj0uoCapGQBbQmM6fGZZ7TxEZ0Pzp18YfLDGZ/h2jbhGjR0 z3GySsaOZd5f0TjBLdy8D7l+su6NQ2fw2YL3cKNlSY/rdvv/KoR2NuwQzfFvzvg= =Bar5 -----END PGP SIGNATURE-----