This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-elgg-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 20:56:25 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 910c3dd4b2cafeffb45c60119b9591976033bbd5 * md5sum a1fbfdde728fb35b401a07d06dd3a6c1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrlRqAAoJEIXCXpWhbrlNm5UIALsqtBScLrdhKl//DXkKmjJK 0agNWMWbRnIzmfUeSYiHPL/qj4MNZF1g3qXNYAlJT+c3dIacaNQIPkRpJ6v+s5K5 +7Mih/MzdJz1tTq4dv4eJNkJUCKLXVxsJkpqycESpblNsvwIawODya+hwF+NP/+6 Kdi+4pBOrAjkD1Z6UijvlZTWf+yp/UrhPjB112sdzF7C65nTfyxXuM8JiVWLEEz/ VPeNtlm+m2VHxoahd/d+ZRZuuzkHrSCruOIjjSQ/G00fMWWk5+Nx0g8eNNAySpgP 2QWkR72L17ldHllDdsgWMaQ/Ds8hnHoWDU4JCqMpDgOfh68uHvNYZl1b5pbAqYo= =uyMn -----END PGP SIGNATURE-----