This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 15:35:32 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum a776857898027f71e48d7891a9f074327cb17557 * md5sum e0281a5cbf07da4109c808271c6c15ea You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM6q6AAoJEIXCXpWhbrlNKfoH/i8SQMgecHrn4zr5W50YcpwY FjXOEajZB9wcWUG+1r/QbQUAFdxxoOm3oTNA/KaQzcyDNVmebU28qsoOG2l+ypoZ ND4aT9R0V8850071CgWTm64Mm8r7RtMn58hUIARw7L8k/uDrPbmPZz7dN7ouUt9Z bcU2hAFShX/MTa4F282DyVlPKuUEBD2RLXY5C/YkIiyWO4QPhOpPxCGGqa0Ic/K7 AvnDq8VtbuSxqts5uTh59XLpCqOLnkOzCMOLifijjj6e2IF0j/tfzZrw4lmSok0E En4smDgoMTlqVo359kzdTwO0B7+s/cXkWyKyGffA24Jq+Bh1Y+xShLoROvVlFsc= =jhUi -----END PGP SIGNATURE-----