This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 08:20:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d94955f15c4e0b64b6ff417d45b0aa0f2825fb5f * md5sum a2d7a20a4d1d08b0a076461b13a4c0c1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkxXAAoJEIXCXpWhbrlN0TEIAObfAByUIehUDtjeb+fv/+87 s9RdlRU17u7ejenEgnk8PzmtVinX4FVsstn+YwIuJySFW5KsOSlSeSSBbNkHzYzJ C9UwhIJ3NfWxJrRD3ChMuVPNt10N5GlNNz5+qrh6R0OWT+LF4Sh3518uN5M+I4pR WxW1hqcbdGRO1awT1K6MLAnQqFIwyzCHU2CkIfH25LWZkFQpT2637QwcHL9wu+Pk mC3rVzjLCB/jrcqzlJxoUY5ABEeBRhB2xSWTG3dbnFZATT/eHRMM3Ka91lWtecwm sQRNblgPYSP7/ffPqmoX7VVdy1b0ZhV0V1V1Jvh1XTILfWWbwvsALeJa/qfl19Y= =BuYY -----END PGP SIGNATURE-----