This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-12.0-squeeze-x86-xen.tar.bz2.sig gpg: Signature made Tue Aug 21 15:50:37 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 028c140e8cd5caf17eae99954dc7e5bac0ac8c52 * md5sum e4bd7006aab745e9611070f7fc0cbc40 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM65EAAoJEIXCXpWhbrlNcZcIAKoHDdEpXJktEiXrjJyLYszT FIaU702ycCXbPob8yrc4Umz4uMO+Nc04GkEZ0bJ7Lgmy3ENdldVcyVkiQSYPoTTS wGwVTjICSYrqk8MySCcbsEAMM81mi7JG79dHTPZY/MUpDDAeXnARcevNLPNU1QwA GpgRDkkz8ZcvDM0+vZHYNla5oQSK5b8hx2gFa+UB2G6IgWym/EO90Oa6TU0U2Tck WSym6zglMY1oyElWJ7g0VnWSduywIXMXzTwBMaS+zpmLwVkG5UPd9tllcgheVyXv NBW+Yl/JIOwT185WU4luoiRY63GtxOLHyWi5OM6b9v/jdJ4Xv2IlKvI7R+7IaJs= =nIis -----END PGP SIGNATURE-----