This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-plone-13.0rc3-wheezy-amd64.iso.sig gpg: Signature made Fri Sep 13 09:22:53 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c241b5c5128e79e0aeebbaf6e7f8b0a25ab5abcd * md5sum 1ec57ecb15431405049c62d939cd4602 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSMtljAAoJEIXCXpWhbrlN/fUH/0fV8wgk8gKq5N/0Fgrs6JRI D45KLiaIeDuzN8lgA7EXcoDdq+v3+YM6rC09xFY6g6mNRDBfu0VjvL2eKtgeRqXH 3IItaIABANjOfqLZZU53uEsmfqyz6dm1jBwQFmNP8CJkRdOlPooeCiBPZPXvn2VU UTqCZF8m2O7bsTSfYGb02268G6nRZs/hzhpFB2BQeDjKgT1WjL/L7HWET1Xd7vX6 BIEbDN8ds2t9qFMGV9vqWHlyjjv3wR8AeToHrRJ21UrFdGT1FRltHeJjnM1C+fbR wG11Dj335iSO0sxog6/eky5IL6xBoc5DYxgeMvTb7SWhCP06IwUGXqujLWB7r2E= =/dCv -----END PGP SIGNATURE-----