This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-magento_13.0-1_amd64.ova.sig gpg: Signature made Wed Oct 16 09:01:47 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e43e2e3cb5601b7b6137fe90c0d5eba237f1e06e * md5sum c545ab18bf24588b2b6e99ef3aa58119 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlX0AAoJEIXCXpWhbrlNEh4H/1dmPfBBO+jc80qxK3DLiy3R cqMPiuq2HS9LHgJb9UhQ97yL+7kH3kBPWtPCknoXX4fq5nrcExMPbjbOsHHW/Uxm lJkj0h/H0k5yEtwxX778zr7Jtvkmvj6DyPFl1yJY4VRk/G0PpXGgvzgotXYoMjTZ 7wFRTrgF8PlWvpCbmG1bF2oMTV51BLt9g8PCA3wLi/ejmldwzbNTN0cS8+PEjOPt Vr1mD9jP9QVnRiLym5WpwQlktjqu5UEk9FZ5lpLrrrvFmsGMrQnYoH/vGcJRPgR3 6MhtyLUOwQTrSFajOfayjB/iM2oShqDk9RtXsNGAfyEInaTs5jWBv9Yy7GdrHrY= =AkHd -----END PGP SIGNATURE-----