This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-deki-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 21:01:31 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5e71b4bfedba1999189caa6b5a18b885bdd27427 * md5sum b376728c66df988f4e163211d1794312 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrlWcAAoJEIXCXpWhbrlNh9oIAJvDZhGPrLTadUI6KRY1coQs uYv6uYpHO7fN7HuvF/Eeyzvsw1n+9Y7KW+XThldROEFFimzS171YVEoNoMBmuRXB mQfcxKenz0uBDU+ZslRNEMrn4ooVsols/jzSWutzr7sI2+shrmJXVLLgzFbQ2EjL X9aUV1eDcWadq4gpZ8SvYdU4VymsJUmVSzGOdC44SbagrVUHMRJC0m+64DJ0AJoC mX1K+0Jse3cYEz0aDlbylpBRpQuSXm+2a4lRGz3TY76tCbx2sUDUjxFqUaSaQimx QRL4CL05O8xNWKJA/MV2cFSR88agyk9VU93B522oKK6zwo0Q2ZDclQk9lo635uw= =vOt8 -----END PGP SIGNATURE-----