This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 21:37:10 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 26d0abc1d897799e8c8a2dc00399b289502ba77c * md5sum 1c245d097535e65900812cfc5549e377 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrl38AAoJEIXCXpWhbrlNKakH/2bUG96rCklW+5iVmfsYe8Z/ YTzkXMqy7O3mOp5c4/YCwQ96GqZNDcwiDSk0sQt6m3sfoAu1bW/Eu/sKTjAwDRa0 hO2o+GnYpkTrqr3UhTmLfINeXbUxc52EfPy1VJJ/5nS4BaZZ9egd7Gq/YWL3Sgxt 9/+wgiHSfJIFIKxJZfAYSdDY+8+AyNDp0yfoP1hN1rZ5N3DnWMvGJM15/iAtYzSz QILKGfJ+3Ux4mmV9rw4lhBIBd096s18g+9pnkQNpzGBXFa1iZSAimoI6Gr1AyY2M dz8TPEKX+DRSpZBPSam5nYwhXqOIgHCSbeFKH1BV/A6q+rvZUmYBSmDIwR/uT3A= =21sF -----END PGP SIGNATURE-----