This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-joomla15-13.0rc2-wheezy-amd64.iso.sig gpg: Signature made Wed Aug 7 08:02:21 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 28cb7555e67bb43e230ce835be81091b04aea2dd * md5sum c990216dbfe9531af55f6af1e1ddbc7b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSAf8EAAoJEIXCXpWhbrlNuK8IAM3fuc4MR7sozN8OuXpuDvQx IFdBg9JRQ9lVXQiYPngxywQOAje041Rex5X6GzqbSwMY8IUay2+I/F6eTxbBMeRJ ioCd23kMtBpzIrQXsWpVJ6RP+ch8eKFwywch7i0XeDDd51nXg22duHf6PrfO6mQL zymXYTrq52zI+jI+omT0cmiR1XfDfzQbLPbBJs7UXH70SQq5+LWFpSI1KselWSv/ OJObTslFwjgQe+bLJgdOgs26JF/caEyt2rkItgeIhT7OJfx0X83wUWEa+ihgOmIp t2EwP3TT2UZVZ0NIUJuRxe75Wi96gizhBt/BnQ0lvmT6J7VjIeMKj+Mxqhc3Hhg= =vHn8 -----END PGP SIGNATURE-----