This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-python-12.1-squeeze-amd64.iso.sig gpg: Signature made Wed May 1 12:10:33 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 433cfa005437872a716114ad415af1b7a2328cc8 * md5sum ff51b7213c8882ac698025fc85b4668f You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRgQYvAAoJEIXCXpWhbrlNxlsH/24JSpHr18/94U0IOR51aLjy Y9l/JmI81367zQcV1g34vF7MI8BFGfZpzKlGzBAibJ7/ADdtUDGtNNSkW6XqVqiE 8TIoM/g3qrNyBUrsVdrz5L4m9MK0H3FYuoH9clq2Q9gNybdlcu/dfO1HGlcVAquX wFRjKaMbPwmpsn/3XRZrpgMFn3gUG4k/fPThX/dbZsHMrmlADiG852rvXwSz8aZQ AF/DuL6tDLcj3l52TfHr1c/+99m8xuIdiD+79wGqief3Z0BoqlBXFPPkpP+Wq3+D zauWdNmnqjpRdbY/DYIztW0HtaYs9edzS3keOLAB50yN4tGTQAWaEkI1W8AdT48= =JTFe -----END PGP SIGNATURE-----