This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-symfony_13.0-1_i386.tar.gz.sig gpg: Signature made Tue Oct 15 19:35:49 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8d459263befe25befedaf602191328e2f0dc4dec * md5sum 93c47f527dc28888fbbeec7505b6a341 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZkMAAoJEIXCXpWhbrlNnmQH/0m+rLz6SzU0eTUtC/y4SOxR qBlMsNNpjrb0DKbZ++aE5vSVpn1JLBsP/E8FEQ319Ua4pzsVv7bWOy22Fy/HlmMe bX4Tb7fZ+JGleIj+yQ7nTkvWVdnpubEKAmewQaw8Wid75iNrjbx0Fz6uj4ZqNXUn LTNU4j08CCUK5mykBVtzKQ00dp85yq+0V5otKb90gHyyyNlKZa37fhtx0g6WGKl/ 8iEqcKYRzs2tnoh38owdbd3CbBDMmrT7sAds70uEN74NCZ+EQxHIENr9WK26Oi2T aRsrafdZuE1dr3gAAYV3TT6BdB/zJaR5Db6s9PBshfbVs7dg0QFhh4jXg7+6Rrc= =x6fr -----END PGP SIGNATURE-----