This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bambooinvoice-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 19:45:00 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b73d90fb9f45f6b71032421c380702519f8bb41b * md5sum b78e0f52f5998cb75855b40dd1afc2e3 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkOtAAoJEIXCXpWhbrlN8bUIALSSHEDwZvlJ5+5fL1coL0nt 4huwDRoSXi0lSm6HW7UXYdpygE5mcEupYS/aecUdNGxYK7LUHAsDZrxzkz1DhfEf 9ZnVWTEfPv31P3+Q+ZmssFmTrCmpglF12cuSpuR+lEs3Hgbz/7sKJM9sI9HE5vHu H9aVSSkvIHDLN/Mexr+LlM5e4tOrmtwdcjc/Zx0PnO3WB74C0XMfmKDJus9556Ai WSTETf1Bn3dgNqj42HnkQbZrcrE+fgCr0StRQC1Gfube5LaqyyNu2BF9ur32qBLY HzwaO57ZVOn89x78StgTg1rtu/q1PZ+iEtRRMt/z158Uop9QWP96x0fQP+v1uF4= =t/yI -----END PGP SIGNATURE-----