This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-ezpublish_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 16:02:10 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 6c8745ab1f4ecba523093a16a8493070ab86d015 * md5sum b89fef21c351f47ef960d7fcff5f4641 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWb5AAoJEIXCXpWhbrlNJ/kH/1ZBVDJR0G6eo3PruBRluBB5 AONlHnmoWMpowog1u1gBqBGJJhmbhREX0kEPyke3jc3uTYNptuS4Yr3J4230vIMY Bt8AR7niLBLeGOZgW1YgkkCAbk9trXv18xI0WhczkArbxJkse2soBenvCYipNLxn lHw6K31awNw08kR7752r972WjXgSz4CyaZOjxl7Qom1LEdCjnr+5HwSK5HfItrbG 80/c8890rbv+rJOa7nMlccLczTaP0rOh9UrYpvI121TNkv8+IQzSql48DucQw5yC cyX0nw9XZw7iuqSTMqT3JvHS6m6W7DtaHI/sPTY/UgmIEc4vwRcniyPBXfOOqFs= =TAAB -----END PGP SIGNATURE-----