This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ezpublish-13.0-wheezy-i386-openstack.tar.gz.sig gpg: Signature made Tue Oct 15 16:09:16 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8406662f81aa5d90326383c8eee3a692a7ce39e6 * md5sum d583d3a359f9765e117a73bb7626abf1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWigAAoJEIXCXpWhbrlNl7QH/2LG35WGYqlq+Dgauyze4/dU tgewyC2UcHuJAIbKV3SK2J47v10xKqjPfYGdGa7dU4E9UpqbwuONQRzEuIjJAs8h Cn0m/KG+ufiQhb1mHIIkPcn7vzK31NQX4o1yv/MOTxR6sszgFeDeMP7vG/Qu75b8 IxetzzGw7Scu0FursKJi2x73i7JhvJF9ZmbK7HgLJO4i8DsObUSQmGJcmGPvypIw UXwyvJwnO3/s7hrTzbd2DnVoeZaAhsXlhFTbJjS5FH5KzJlqt8L2G7k6ZZx6PRzp +w5gDktI7GZsW9K0CUm0hgv2ymR8VdAYYbj+7uftEHsQZUMuCPW02g9w4obcCdo= =NZ7L -----END PGP SIGNATURE-----