This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-piwik-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 17:55:57 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 78fa52560eae8420621eadd64632a7e940ae983e * md5sum 048341c9cf832142c2c26052ba780c7c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXYGjAAoJEIXCXpWhbrlNlzwH+wQXYwbUZIjVUcqxzgCX6HOu 6H2OZLMiau7nv52VQLMx9gwAbWSybPZxFgButfoAMJIpU3D4xmb1DfEi+ULbZKHt fwmEe2CR9fUf3uIRAoT9UF+mUQDjmZYT8y5jdycIYB2OZ1SDaOpU1E7//p7Phxh5 Iby4Ro3EjQ9bkqqem2ETLdwQuGmioRkK2a6i8jrmeALCHL5Kn6Ci+wBdIkntJKRv J0sV4ibCoZM1u5uxiFjjsa8MzP+SQKcbGTEPcIRFQcWYsICJYuCjMZkUzhSE0m8N 2C7SbqB5G+oySFnd2EPoSTx/xFMW/xIjtYt4uuqIh2Rf+5XfQpTk5URIbpAPN3s= =4F6+ -----END PGP SIGNATURE-----