This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-osqa-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 22:52:25 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d5a427ded39db6da79255a91fddc5b6fb58aaffb * md5sum 0f3e961f33712de555196bf8a41483a0 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrm+eAAoJEIXCXpWhbrlNbKMH+QFWFehRa078W3CAM3un1LYO 5qk6THFd/qujwptRZt0/4Kp6UoM5TB8NcLVcGBRhTod5Ds24Ckc6Qu6jhtbbm7wv sdF2NI/pAx8LyT/qJarHVdOMBnASrlGBjmreK61JqY3RdMTKuqwnZ0RmBvMHzhY3 L+oUxnbJOylGoR4gjRyB9ojJZJi2vt9ipttNAY2bsBL+jBEjLU6ES9Uk+vq8RpK8 vRWg2kKLFCuZqjpa/IRu9fcKbPIZoLmqlROaxmPFYgV6s4rA5Pauav9KthmIN+iV BM/aQHsaqAk9P/eVcQHbSrHhMbMvvpELFZvnlF8vv6LdSy58O2MM1R1x5kpbD+g= =t4pZ -----END PGP SIGNATURE-----