This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-sitracker_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 19:11:17 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9f07d80398106a719b3582b1b10ef6c10c2da0e0 * md5sum 6bfff2aa99cfa385c86ecde87e4138c5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZNPAAoJEIXCXpWhbrlN0bEIAOQdtfoXEdhI6/a0kq3wa5g2 QVP39aB1+rpjWxo8b3FrJKvWK9SDqYjW7c62ajOQQdV4MT1oxysC3LNQgC98Zg0t gYFeTNSISRAAn1tUVeRzZw9jCdPdk7qPX3bA4Z33PedsJNhF7Vm4yQIV4+BPsdFH kvQeiB+KgXJsLctmW3uM6VL/6zC/z/2B3GcaqlQzHaKpZOGfE8mLwFAff76/LB7e RCJpG9cj0s8EE/Y9FWx5qY0eybh5gF0evitf0xKj/HMsNwvblvRmbSsZxACQRy3g BUoDuKHcpwGYrnGpQGMQSdkoTYc+/JSJ1RyFgVaO18wR/Sg0Mp+fPmi4ihtKysM= =xhXD -----END PGP SIGNATURE-----