This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-simplemachines_13.0-1_i386.tar.gz.sig gpg: Signature made Tue Oct 15 19:23:49 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum de8a4a2cdcdea00df8aa43fc6f6465e3894c8c63 * md5sum d4b91d359bfa3705b316accac5ba9593 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZY+AAoJEIXCXpWhbrlNMUMH/jCwkaCmjkNUuoEhuQvF7v/t LiMlQFk1R5M2LlwtrZdsMBxiEz9yj+9ufJTLL5wbshfHH/o9T/rO9lnwCSRCfKHW NYq1ll03EDje5EBgAOqq8FT25SKsWNeSgC6IAg+7AG3tI+aLUC23Mc/3MylWrUuy kT+vXYmPW8LSpyhKelCIXcpEla6HOqGgve+ox0kpPfdNays0pQGCdHWE41L8ar/C KEWsWIlbBZYyiS4HV6107xokgi/wzmlDdwDqL+QcU1l6NQW92GfE2jWfBJa49h9y S/h3pA/+eNQzEoi/unM7q1FaC+BXcny7gvl2/8PbVTff4CL5CXRD3hLD4iViWeM= =lALV -----END PGP SIGNATURE-----