This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-osqa-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 23:07:22 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum fdf6a8801f2d0556ed628b9c2c71a5d388cad891 * md5sum d222bd024b567153e8977eb1e37d4bdb You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnMhAAoJEIXCXpWhbrlNryUIAMxfb+FuCs8lfrq+1ppWXdi3 Bz+ZjoWUmYoZjE1NtijWFTX1qGm5Zuylr4cxO2BUeFyu8V9kqEHPjr0rRsZSyLpY IMnOrLNwiOGz/OujM2vCQiQfLWkcTu3osIAQZUDk2iEuWNJEaQ4XTegpmbvs4G16 d1bkmwC4JRGWAjYq4cNeid4KFCqI57HHdBv22G3Q+cKnAEOrmfYxero19TKYLDz7 +kZpWA1koaOxwdk7e9R+KQV0Y/Q725D6YzK/zuma+75oSznF7CEs5cQ4ynJpN9mB 2+1agEawhHXj1U642Kj03pbXz/O9hI4B/eE5TQO+aZFPHEadZXQLB7jW5F59XBQ= =bJCd -----END PGP SIGNATURE-----