This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-statusnet-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 16:09:39 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 58c404722b44a6367294b63744ab7a2b721c762c * md5sum c66c875cbac5dfbdca18cd7975b9bd15 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrhE7AAoJEIXCXpWhbrlN4gsH/jglr/5WcACX7vLGS9ooeu+Q /OvrSg6ZmJDNnrHWxqQGb4+2AJfwIwnPvR9lMvj+mVFPRxr488OW4nU6u4wR/IUD 1xWnBttuX8p1isK3rgvOg85v07oeYAiZkvLnLFLl3tPgDlRSltf1Pxa2JG5eNMBm KsCsbhLXjK6ufx2aL/n8OhxxMLfhbOX+lmrcwEU3xkS/MC2/mNNLvNate3Wfev3p 54QBV3jLc2HciJiEi86MT7eAHuva/k1fThDYaBMCIo+tgvtvB9s24sW/80886xN/ RTQUBrzB5/R+kPG43UqfpSlyn30QZ64KwXkKieIWpdFQD/15Fgo2moj5MnU0nSk= =EeD7 -----END PGP SIGNATURE-----