This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-12.1-squeeze-amd64-openstack.tar.gz.sig gpg: Signature made Tue Jun 4 17:15:32 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 05e584041e86d0952c00f43eb23e4a330dac9320 * md5sum 1eee2188bfcd9fe3ebe0ac2c23a78922 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRriCrAAoJEIXCXpWhbrlN5QsH/2Vyj81+wpiaGlEu53Cqi+pw hSABx3kZ6uhKH0Bm6DNWu1o3RxfTvdfBPpXyVeLn9FweNRyX/HTitgNcEx3uF8uS V0e+FzkZ0KXxnYrEHweDX65CLGVA7RPG+NwOTxnixEt6Wa0DLPx7hR4z9DZ0oy9d jtDFX//M202lesMdr6FEqWMMYB6elMnxhSm3d4IW2Gsw1Nn+UoDTEMooRVABqamx istVH/XmWvhvsuMrgWAEhaHAy1jbL/VhezOpoYo6RusFb6Nd0clFQOY/D4caIGlC lvPLjR5Q3F4UUftENAaZZp9lgA7aC29B+YiuTanCYROQwewLeK0lXx36Kteyx7Y= =XPK4 -----END PGP SIGNATURE-----