This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-drupal7_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 15:38:37 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b6c0e9a81ed941906ec8079331704639f0050f47 * md5sum 9b6fd391c391d666a75934b76132cba8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWF1AAoJEIXCXpWhbrlNEzEIAJB6p1ax3DF7EY7xpRG96NG0 huPsDe4xXtovQYwXj1cfKBNjCi+TcGBxgRoQSvb/OepZso9OOzoCqfnvWEtvTrXd 5Y/P0WPL8CT5ckgsJn0pTaLW6tHEnVSwxMKpV8K66oso1ByQxXBT9nzStpUNaN6n K8lgbQ8mdq1rB/d4gtRM+N+Xg3EuhfxRLy2wF1RUNvxdmB9dVjvPqvhTv36PfJl+ MhVAl/5TJhRImVTNYQ/1MM/O6f8DlYOastGfnioCrT6btiOFU20vCin9alOanp3m 3xOdq7eJQoFqJ/ATXdOGx6oyDw52YqFk2J9IFF/nxkUB8CDARB6y4R+0KoyPLoU= =YTh7 -----END PGP SIGNATURE-----