This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mambo-13.0-wheezy-i386.iso.sig gpg: Signature made Mon Oct 14 18:00:08 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 56ce6d39e1275060d30fb8acdee953fce371f9e2 * md5sum e2a68a4781b1d52693da304e64045cbe You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXDEdAAoJEIXCXpWhbrlNwcMH/1G8JRLOYETnYn9JKZneM5dO Cnkny4r8e8pkjSv8/+kr4Oiac9BylYHQVP7m/HZXjF4jwHjWAiL9sJ6Ht4wxHPc1 ZcHJa3TUqdGrO5vvFkUv8Nf43PYaMYJSN/y37c91tt97/PEHExIeppre9s2TzH6V I/4TrAOZfEH2eHEDHGItwkNIOMVdsGFacuobvAO4Ncw1LDsO4W8UH8eLN+8jnn2m VWNAKM14VOpxLYo0G+m3rpwZcb7OQvkgwqgYl6vQNF6stqFCitvN8547LuNlkEI3 ccjG0HkecDiY9xeWyUe0yJ69UqSQb27gZNwpjmo2h0xrcftlbM5v024aWEb6+HA= =I5Ri -----END PGP SIGNATURE-----