This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-openvpn_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 17:31:41 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 395e4cb552c82af1a1def1516e36511c0eebef6a * md5sum 8dd32a64465f06f5aebd788589642b55 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXv4AAoJEIXCXpWhbrlNgngIALXLx1ANDqYRcrrN2lLWQRS9 e+gO0KnXtLSpDklQDvh6G23P0gGc/Wlwm0wrX78LwOBJpEnezOJ+euP3nGl1N0ok oAKPj9GjQV+nB37zXhILo/P44XmAJwkDR1qSmC2kvx7Eu5j0am1Wem+fGU2foM7Z CJEgq3BeYR6dy+D+Eg2yxNeDcmQIhavY7r7n64GyIJs9I7EF2NjCVReBZ2d/HDac Pi6M4ZDkzkcJZXGe/W190+4q/2MJPd047g/x3H359pEte5EKPMo7AJ1fwTC5Bm8b Fg1HcMR9r1HBrmG1UFu7LvvDhXBv527ScizIJXmoVuEoHlDJCvFL0iSUOs0CWwQ= =hqzX -----END PGP SIGNATURE-----