This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 09:04:29 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e88abbf2f603db55468a2d2662066c01d40e8501 * md5sum 960dbe46699147bc72be130a1e0ccd18 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlaVAAoJEIXCXpWhbrlN62oH/38h3LUBWEBIYDpvSHHWrBGq 1G2vo13f4Kq3otXZEw39i9tAbkze3JDm2vgMCFnBrj6sMMLqFDmfcyCKJHuVl7xt CTVh+4pEUfrUULax073jf5LN+u7QxU1PdKv1PqUO7wDw7O0M0bJpw67ApRP2pGTM 6neU+L/7tj92A7iLhWjikddSoHYCyBHsSfeMZqlPz3vs5guSO1yNYub2/iurlgbF tk1Qo78j4VAvOhDk/uHx/jN6QfP6jHTjU+c3pFzYzRR5etAkAPhdnW4ROkEHrzNP Y8MPbvPvxOJrfXjmLIIhTGoj9jC+AXi7in+FA0cauosExscEz0TNw4YHpGsm9aw= =iiX/ -----END PGP SIGNATURE-----