This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-joomla15-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 13:38:56 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 3b68d50c5c24b41fc7b8c5b0a44b61ea0a99403b * md5sum fd961f2fe10e0594e00309b1eb07647e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRre3lAAoJEIXCXpWhbrlNVZMH/iPenzphfRKQR8fl49IZuNIq VRKLg2vBkCn4nSHjzOl20Z0R+9jn5FXD44wWQyrtqXH0penWStnFY8opWR4ODyrQ wPhATa5InXihcQ7W2jUL0gVLUoFMsh5HdoeXgFvJkKaKYnnJUOlfBpJPH6P9gMHX nar+lpaANaHlgqIxXRIqihP/MAtuMp05yySHvVSEMtU293+AyKuxVv3O4zOmionw WZqX5Dzh4w+2HvaMBA7385AGfIYVWYarQ0g2Y90LOARjWOrT24o9os1BVYI6t1ew asMCmS8li0fDi7u61lQzF9jzol3f9Q4qj7K/BzpRPSfzX8tH13J8/7Wu/mpBQY4= =BxTJ -----END PGP SIGNATURE-----