This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-mambo_13.0-1_i386.tar.gz.sig gpg: Signature made Tue Oct 15 16:46:51 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 2b59bd7ddbc4205c1e9ba589b935e1ec7cf2ddcc * md5sum e107a177690669972d36c2f0ca143bd5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXF0AAoJEIXCXpWhbrlNzWwH/3K04wG6bNva4CYJ1I+K1Unh +amrVBof5iyr1V3vav0HVbZV7GDLEgMMy/dg9BOecm99TeICc9Vl1gsDiA4Igsb8 TuLRbrbIGvTu5qIX5AFewiIv8oeDzv/0TSUfpByVwmOblnvcQDmpafDfc/v32Lp1 2VlMoNbG9ab7Xtn1gXzT/eP7ta33xRq3/4AuVGB8+GNwH8CHfFCzJh4OqmQ1YbY6 PfIA0AL37+yghpKdI86pSDRZOpLhbnPxLD6ZZM0Y5JgXEp9wYrVyfoIc3J/k6jyc nds9+jIwhApZ8c6qzschrvSnURDcJcoymSLT/EtfO+XUqP3Z5v3JLzbxe1qVzek= =hWT+ -----END PGP SIGNATURE-----