This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0rc3-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Sun Sep 29 09:16:36 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d5419c34bb69bb750a882d1e732ff6143ae33069 * md5sum 452cddecb9b8b6ecfbd7bc054d61d98c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSR+/wAAoJEIXCXpWhbrlNzYoH/02uzUNOJn9WMSSxk2kU61Tn 6d82/GdWl7Twq4v2FiUiiMeTbf0rszy8wJ5TX4P2Zd3Oa8sBvtbfXuEflQPETrcN o7umpmm2VcyJBk1e78ysVC3wTjGlkoqGFy6Iw149G0+CJO14KnZpp2d7orbYg95c MzKA3NwW3LVjxytd8ZA1ubKuOwUtFNpOzd218cYh8KNEr0vmUuqgpkYSoXN6FCji aTDKQ0RM9hVGCqnPTL8+YcpzXWqlJXQ04kwFuEWZaDC+I/4GpRsZ3htwnXB8lZLE ldig3R7ndpDuOtUVDzlOdIHK4NMHvlJQs904FsGgEBkow+lcGlyob8vtm+SiaH8= =vUGI -----END PGP SIGNATURE-----