This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mediawiki-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 22:14:38 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9e3c02c473f2c0c3e76848f8e1a88ef498e983b4 * md5sum 24e05f40db3558d0efa979b3745f4a10 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmbDAAoJEIXCXpWhbrlNadMH/1Snyzu5AtojTntyql7zs6H7 jGrCG51r1QI8mqxWuq8FLKLw0miUcgvaRMsTatDoqT7oIfeoS+EUwoSOsHxH/3Bl rmxRHfqVPnk8uSGhuFLElXL3liB5P1y4SmkPQafmFx5sKjgiTSOMo5r2YRYvJpaJ K02WV5ZrVM4bLpBhVdBKA8P4tZULPVgew2hxtPon68j75RwneoX1ofO3dG3TA34z zq3oiCDDOXR4J1MxBDcSgXUueGxc+AF7iVFPo5tzMtl7hhl5inQDLU6H//l7n11a feL9puWWRfr/jlj9mXtQhztxB38QjT3bNfllZibv26V9imGVi7K5ut+tfxIaq9w= =VvTo -----END PGP SIGNATURE-----