This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-redmine_13.0-1_amd64.tar.gz.sig gpg: Signature made Wed Oct 16 10:14:14 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ea8a3138b469c713132e67d330ce000d701f5116 * md5sum de12bba86296d85a13e2de03c8e86e2b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXmbpAAoJEIXCXpWhbrlNNCkIAL4305yJKWvX3tFuUlGp3bWk g/XNkNiiapDb0ree/W3kfQsH7+p41E0dHxEwHNjJA9y9S1VRgYbrIOD36KCk9uxn P3s8vZtlgwHI/CUzSKg0hk5wCehPdWaiQpxcYgOr6d+rWvPjW1ws5dl6ofEMkpIb AOxiqcnqLW7fiJJR1LSMpgepJmzPEwq62HP8exNjS5vilBIwLzJRAHXexj6tMGrQ /shGEGDOLFL7quRpvnGQVMmZQZ/Rh4IBR6pEcBldVaMQK+eLYpL/fFO0FaK4+H+V ClL4RRd/oyPzbpqw+2xyhlaEuMs1Kf58CCPI1AOK7zI3IUUkUh4AqohrsCIvmlU= =WjsK -----END PGP SIGNATURE-----