This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-observium-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Thu Oct 17 18:07:16 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 17765b5bfc420339903f8f8141804dc1cacbf680 * md5sum 3fd92ba83a5f42463bb37ea6c332fc46 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSYCdGAAoJEIXCXpWhbrlN1EIIAORwTyuk3GfgUg553ei1sIlL Uib5OvTVREfrYG1lRtr16klUCh9eUUucV2ESxlMEJJQ3MclPTX/Oa/5xaixTbPow iIpGS8C3h/zO81Nf7CUQpmehP0onzCwwevIHTBPNfiP9rAuxIRRjGw+wF44egJ7/ NsT6x2Y3uFsu6LTr2+lMdHqObH/Aeq2bg3gw/uoeyxYhJgf4j278WSwVCCmnKp1G HkDC4+eCW3eoWDIOvRGnPnpHb7gnb415q2FulOEqWlaBhdRFBjjewrNhBQji6gRv gkkSWsFnIKq54VFZb54kIdFPJ9XiTC2WaWhIokkkRWydOCOyGb4tueS2F7WujWQ= =eQfz -----END PGP SIGNATURE-----