This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-python-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 12:39:20 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e43192ab02906c67bb2021e581139b2bebe04a6c * md5sum dc4a0c1573e9b92e4e2875d2f2198700 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrd/vAAoJEIXCXpWhbrlNvhsIALjKrHukKK+pe5zbTY7m9T7j mF3lDhWPSeUUqGZJoX8G+GqByTUQ3+gPKABXpkEwZQjPAwYJym/jPFnJZ3qSjAXz W+3ItGTxxBYFbYA6ejc/kvYQNmHS8msgF1rUMpbKYo5VRklBjlyBI+CdOV+0czF/ yxFHkTVZ6r8P3S8wjQ88PK36xSgV7j0Nn8pcl9GP7xHJFaT8KD2ocopSPpboRjwH 4u5jO3DJZZRW7DrRw5WXHLrPUgibB33lqSYh6iNBrCewzUOx4htIgWbVlgRkgbRe y2czfQE9BdA4WaFBdeSsqilNf8+1VY1Akv/P/MzHzy5kE0e5vd7RbmXjAsf71ZU= =/Eal -----END PGP SIGNATURE-----