This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0rc3-wheezy-amd64-ovf.zip.sig gpg: Signature made Mon Sep 30 14:26:21 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f14df1f983f75c54ca3f7db5230e60e3a7d5f54e * md5sum b2de1b8bd44b676ca507c7c28d719d52 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSSYoFAAoJEIXCXpWhbrlNcmwIAIPxTruKIS6Hw1qZXTaXaJCc 8mjE9vHnEQufupZOCctQrTrnWUS5UVW3AefWvLDua/s4aDu5LAAAYb/0YJ1fFBZI 8voo0MUHGUJVxahSK61uiLtnztFWFj00Y40+e1CINg03ARrJoNpKtevCPlbu/a6q PA3sHAglXRycuaPg5LVd7by6xtGb+0g+kLU9uCVvI3qXWrfUzXaKMiC/V4hKmWYl beCykYjbIUJyPsHHsDuihjCaZVDH+hkGwtJ2YYvmk/jCB5OSi9hQjon70O/XjqAz a8NxRoFQo3dRsl3ZGNtd6vTqImm8+4k0W9iZt0IgLhEWlJ5P8vy7UvYQfEerqUc= =v0c3 -----END PGP SIGNATURE-----