This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-roundup-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 16:34:38 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum a93bbe737ade23ca61123cbb3157de96a4fcd57f * md5sum fdfa0d807b6139513e503f94e8228cf5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM7iUAAoJEIXCXpWhbrlNiLIH/Rd1FoTmtkwsXa2JfDvWhknJ pQszSd5G0/Y1u9pwmhOr2pPzSsHNxBsP+Q0Xe8+wpcuQvJ4092yrBPwdsuuSqZ5E l6rC4Vanmlg8gNVGcT+5aLTlzUWsdKY06Hy5FlhqP+Oy+6+tcph1CUf2kiSyLKoi tuKqEGvaHEcR7ctxs+aYPO0hnLZTlDGgyZI0WLXX2yf8Pd7BZDQUgPOUiaNAFRkI 5zRVA/Ddm9Cx6Aj88v7S6BqRYl1Qzbz0X508xfKUjCZTu2l8qtQZeLZ+8eq+SPKX +Jebb4ER+jOVpH5JmT73xoGdSVExfP9c5sepMBLj3HkEYlgaFo3VZfX0/WUrYwE= =Kgs4 -----END PGP SIGNATURE-----