This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-bambooinvoice_12.1-1_amd64.tar.gz.sig gpg: Signature made Tue Jun 4 12:26:16 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e795ad4bb47a1d4d00455d001902bcb5fad4e5d7 * md5sum c654a7e94ff6178350d22611087be00b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrdzjAAoJEIXCXpWhbrlNc9wH/iwzfmKTsKKe4iY38HUgVEOf NAzRbjOibzaEDPFRV7jJM/tHd7yxJH5JFq40XRZw+TmQoS11IUkEFeTSsgloTzcC 5GcwmD7LQpZ/X9wgRgwdlXwhr0fX1Mi22wQ+/IuqeqACnlPUdDirwrFgpNizFQHv qW4H2uIRSYlYjACR3SG+fW4aCbkCY60137PBcdQ54V5gR1lxI3YNBSmhI7ltmDBj 7K+i5duGINpQelRsQDkZxxvA0tTJF6PyTBRrHOAItgrAtC7MEXfjYDz2DI4s+mkA OwgXixl2HQKQTamoQXUBA1XJvHvinseYuJ8LKEcBP8dvi+4QnMfIRS1BrA9soGM= =eDI3 -----END PGP SIGNATURE-----