This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomatocart-12.1-squeeze-amd64.iso.sig gpg: Signature made Wed May 1 13:58:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c42d518a98a94dd6e6f34b72b899c84378b48d33 * md5sum ae198690dfd68a7eabde01231dc9dd0b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRgR9yAAoJEIXCXpWhbrlNmHkH/2S65e7WOSw7HmUz26gtoGpR 7MPzuKihK+lzQulqSAgL11qyrCi3X8MgmIfH11Foo/zcdWQR7COYht34tUdMkMQC M+hOa1yVKfsWLtRKzA1FdSvG6eRGMXKmH78Mg2NwvLc9q6DculIzCOHHa+fJlfFC OG2D/mNoUdP/vvHYmRjwL8Ikp04qqMEvDLfa2jLbY9uJqibgkY/hAB4XogV/yPsg xiyJ+3gfwgYaHue0OYET3jcztw0HPFHiWbpSf0OuHQ8Y122ZQGLMjudzfQ0LB/E4 +WsydZNWFuZirPmKaqEpObp5UK4J1SfkmBs6j0T38O9n11iqDy1N50Oojm9yw+k= =Ma01 -----END PGP SIGNATURE-----