This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-magento_13.0-1_amd64.tar.gz.sig gpg: Signature made Wed Oct 16 09:01:39 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d0bd3e0cdf8aaee30b77441bc44750745b822d80 * md5sum 76cec11f2c4d2852aa31dd6108db01de You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlXsAAoJEIXCXpWhbrlN7LMIAMgzvlGRcejZIgW3vPCAXRWY LngMM5Q5vqaBPxeklvlYfRhKGZTDKFX+OEYHQ+5QkC/VNi+wF5OQ8g+hKpRa+YLf GmaLRvhDUEHEQrfFFQ4C8iefa0ZAcxMYEgEqDMMEj2fh3Xl/rU0i4nyyK/PIJCNz 2R+gdHlZx0446Gt8Wc9BPzgKhUXRD7BBR22JMK+oaMHAY5h52bKPScp9OnXYvJrH FV6gCc24d8Z1kBF0t+XXPkA7yuw3p7huvz1omuAq2DjekOvdnpuvwuvAmGWfgNGF ODC2SzDtokvoX3Mn116AiIlIDgqZXWXkBN0iOT2Uxt6x4qsABDJDcCa5NiqpJVo= =l1li -----END PGP SIGNATURE-----