This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 17:21:40 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum bf59f299b96f96da28b5f2e2382a18afe967a015 * md5sum a7747ea3aaf96c71bd41190b60b8defb You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRriIcAAoJEIXCXpWhbrlNkcMIANPBeSfkUQMv5W7cxArH4nWh X3bgoebOTJFTH2Dyi0p6ckzs7Dfi0OUse1xkuugDtHMEAdO2jDm7rXZcPp1KAvU6 s+/tJ/VmL+jiZ51Y5pEi/ZRJT0nrNwnXY5iQYRkxdg4nJ2RLo7NMYvpmB8KnxhDQ ZP5PgwubN3Ul3f22asm0RosRRFB4fGmzYZW4mm6dCVKfqBS9KJWMFEWhk8j/Uz10 SR66D/IHpB7SRv/GYjaBohX7s8o1D/dCU7k11K5fCIiRkA2q8QlSmFC4uaAQjcn+ qHFn+/olFSVO3N0ihz5sR3xS57YA6/n0kwGW7jTIEs1474TbVAgzSMeewq2f/+w= =zAx6 -----END PGP SIGNATURE-----