This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-codeigniter-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 20:31:41 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5820cceca9a472496ee5cf819bbd8b614b928d50 * md5sum 86e8a12703734b5a71e3c2b9d46c58ed You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEbBAABAgAGBQJRrk6iAAoJEIXCXpWhbrlNNSEH9RQKEyzEj4b5rHW+llWEWjvG 8Tr5DZ/teFWsyye0vN/7080RMd7qrRA4sbPX3SE8GAZ5RHRARqFkVFvGYyOKvPgO oWRh55TJ3BU9VoU/neHLX1wyBaEZ71Obdsl2xw81bcFDLlYQmZGxPbb5UzphH/tf go6vqJPE5HK+IjB4k0/BrwUWX6/WHt8IX07g2eBWYJnRL7YrlBg34lq7vhhIy9cg /DeHPNlcGB/9J4V46eOGiNkkW1t3mXkVKz4l+EstPdtiWwvDZSUnEvwVnzKF91r/ QQUUJcqVTUkuLz0Y9eJH0ilbbCO6C8OKH+yg56ONgoup+G6M/9cpwO/sUA46kw== =cOmz -----END PGP SIGNATURE-----