This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-django-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 13:08:12 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 94b26325f6bc1ba3a9b065f9e8191187cff43228 * md5sum 2278d19147594f9c7830859aaedcf92a You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrea1AAoJEIXCXpWhbrlNtMkH/2OLvalTPbEA+1oN2vF3fVPP dvi9O9L/gHGLJtuu13GuyRvpHeAtGsPmCSAe+juq7e4k6Xyd+FqvnV2EISGUF4vp n03ZkXaQHEN7+XFiUPFUa/MPx223P/ClffStppUbrTHxnRY1AMf7l0S2r0WdAHzu oDNZikil6e9dU/bPW1AYnFvqQ2RbwfbDG14VzY/jrUIk8GjbTSFNBxkOyPd5sVbY QS1mdv86yoR04RSdm+/B0EZyAzA4FgUVrBj+ZE9AB7716o4SAYK2O2lIMHkQZxmj q9KOK0VkcyYD9W+IPKYjxxWgReZBY1vT88xeAzxs+nlJodE8O0Mmpf0o46gO8QM= =p1KX -----END PGP SIGNATURE-----