This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-elgg-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 13:16:54 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d70b78ad2dd8ae322b64aa152095fe0d07e699d4 * md5sum 1a49b01ed78979774f4a98b3e2f6ec07 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrei9AAoJEIXCXpWhbrlNFhgIAOwKZtszFozcejRrHJ64qju3 2TsJ/iOPiVrSBf6EZTbQe7VicPgLVVSkz9IN83HRUOBXDHSAKmnN5LTHRqXHPsir DixGeUfCXpnF/mLOvFhn+XXupIXV/orq9iSvpTMCtbXs0ANAek1MysiO80UNjGrZ ngO8oeYNhmo4eIPWt/UxXOVrotSOYrmkVwbLmNO32LK1+3YPige++BbvX0aAPxz3 a/P6qKtTUSl+tjRs4vivLElIdNzmPpWelRrlu3YxkFVcipo3urbMkS43B3ql+rT2 WI8COoyAfTAP9dYrWGIPictx3hSa6mXSn+/8vNCiiqj/RIiHgrxn8zqr84CB8fY= =B1+I -----END PGP SIGNATURE-----