This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mediawiki-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 16:49:43 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 516e7ca0c84204c2070aa5d3c961ea49c9077126 * md5sum aff96532128449d31e96634e273c9abc You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXIbAAoJEIXCXpWhbrlNJkcIANsAU249BbXwMl/8PEmT7nP3 68+RYDvcfo7BLrkh3BLFTOdwccoRZCfYrwDSb8tyCzi6ZIE2WQibtVrKPt/EQVRj y0TTl2833wb6lWn1zbqUvvrCKrumerOt15ZdJGMDk//kW0a1GQzoLAoTnxW3I+lc 0BZSyKRIlpfBiRAdXRKF6KrFVI7K1yg+IT9ViDp/b7pfNcwYhp91yug9y+mb7aYI Qe9qxytX+NAPuLTQ98xL5VCDjPNefA9jU04yxm8OPqM5OqOrJdqE7PHwKTLxr671 7MCFW0Y+7Ry5qUMU5rkFNGWXANp/eh0LMffKzYS55R82Lp/Fz85YMtupdR7lrJw= =7iLF -----END PGP SIGNATURE-----