This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-go-12.1-squeeze-amd64-openstack.tar.gz.sig gpg: Signature made Tue Jun 4 12:34:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 43efc77f4c67fcd5ea382f20c4e307339780ac43 * md5sum b64a6279e7e9b436e790811229792520 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrd6+AAoJEIXCXpWhbrlNXY4H/1EHLiVgEewqYmKkQ8BaWDqk USId14nmAf0+CbnCz4DRxtN7gOug97BNQZK2Ls4f0zM8J0z8W2LTi3c9yrjVcE86 Ekzo2PbrlmxMaeCQ4xcsj4+tUbce9DOC74U5fbVMd0zrGb6oM2OCBkvZrcPoRfoL xe9AbuK1goodDYwF9pAqqP8QFmWQsq7Jdw/2iTrn05N7jtkfCLs9Wa+RtWzTZ4b2 li7cy6gwByvKAnG1fN6WDXmE2wOzRhU5VPvboPiELbsU0OtNYjafs+wgyjNyQjbW sXXSqqy5X6GAsSRQC9scoa8vlTphJ9MtOB3UbN+nqs8R3KxSAn+vmsn9YYPzr0A= =4DDP -----END PGP SIGNATURE-----