This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:10:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 7f1a23c28ecaab6ceacd5358249c75fd1e5c5d6d * md5sum b37f3ee3a01bd447cf21dc50012a0d33 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXknkAAoJEIXCXpWhbrlNSR4H/A6T2qvQcjmP8Wjb4znvIgcS YNtYunX+2fLEU9Cy9pLUuKX2h5ZT3ntN0QhrWBYTe3/z+NZIQEPGCELVaj4VF25V 95QyvKFSqZTanqocqHDdfEhJ47WkXfryYTXCkf677iWDnaf9TWcaF53GZjGkWq6H f0XxUOM3EfybNJ3IxProcoSmU94uqA20t0cVQ8qXpWhk6h7MjzUYQfRu24jcOUDa KUPfle7A6j/YCw6PMer2UTw1WUWWeIqlL0OyXi8zx4jb9VC/o9tHfcYGKfKLNJ9W Niag+0uQuiSKaWlkftSCO7AVOKlGSlQ1yrjvy4PBxGlR6VBDnXqv6LHYpiJOxj8= =Pt25 -----END PGP SIGNATURE-----