This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-python-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 15:10:44 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 12dabcacff3df48d4df4a3488e5da4d05a234328 * md5sum 896b35279995f3c4e1f8fbc8403f66f4 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM6TqAAoJEIXCXpWhbrlNCLIH/3zOe1O/NlIp/DtyDOTCag8T lNKwNNcrKfmiy3EKegD5o3Ng4k84YHbLqMsCaUSuTyYFIGn0oFhKZbILxKRUvUXF Et0+oKRTDspbNh0EcvA+tov03GFqCJzAIgD6lrSP0gWYTYYm7IQq2FRiWVeb8r8n nA9zpO5G5RLoXisNsX0JsXki94yb7W8W9LJcVKuhFbaNSge0TB94Is9sqz7cOvqJ kKnE5AgrD559uMMI2r51y8wJXXACIq8earvgPp1pkkGc/6akTI5T+Zx7HMjdo3yq wjFSZS2iojWBGn3O2zFBU6u5d9TJrc9k2a03RI1KuRazSWd54aTFe3ufCAsedEA= =sohm -----END PGP SIGNATURE-----