This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-cakephp-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 08:46:38 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5b6d51f307739924cf4302415f03059e55b28b7b * md5sum 936b31e01dff67e3bcb76f351909fbad You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc2pmAAoJEIXCXpWhbrlNuhQIAMJ3Z+lxN8vOEFdPsn7lQqnk wPh91+3z2oNm84jwx3znGIEEgGXDINKMsYFhTRQlvJcj4CBoBi/83bTu3xkU3Ng8 eREdeqvqh96yzEM2V8y4kuerHcdaJRdnQeFvbntBtdSONMqTfVM/Hbu29Bcjq5MG jeo6BPouUmwy4RAQoUVS+Ma0g6XqNQeZrMEjJRYPdMF/mdyT5Q8f39IIND8nHa8A BRHsQ8gd3vUeDjdMYnPYQUg8XfcpUZIEqvvJt4PxZl0hA6MJk9xlSBOZzFLvZTJw jsFFcXnB3jSfB3vDNn8tJAqNW8CS0mCnhGQDbpsVd63lTCNrAP1YfhuzgYJico8= =TxMJ -----END PGP SIGNATURE-----