This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-13.0-wheezy-i386.iso.sig gpg: Signature made Mon Oct 14 19:17:26 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8ddd16fd3a6a64ccb3c19490d82605d250ed4db0 * md5sum ef1166b1e53f78678273b455bc5a13df You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXEM0AAoJEIXCXpWhbrlNS9kH/1FVennyk+fgAQgUECbvjt71 h1lcZKu4zQyB+eOSGA9T2fRJxv1JjWbJpaXxzqSyb8qzht2mt47N/s3OPiDaOhNl 6+DI0W72GDyFkHdoTeUVvXydDDN1vMBBkhrr9r+k4AHlwyZoFQ4emETVbGG1abB1 JvM9GP75jPx9Skm/1mwHq4ARw+JFdfbCFluheSb5lYPJ+S3md+myb1qtGlzB/4jU trwXA66JW5tfe9zh9eyT1NWc5SAP9YeDGFVkLzP5dnvxaugG7ETyorL2aroVbkSw 4F7z5h+98h4x843HIZAx0i/vK98XE9uitZghquhB2l0vKm+nZKEpaBGb7ktfA1U= =Tjck -----END PGP SIGNATURE-----