This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-elgg-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 13:16:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8f5533e52473cdb0251a85fd18a8ac36c87564cc * md5sum 1b599bd4330a6065cdac3ab895aa24fd You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrei2AAoJEIXCXpWhbrlNDnAIAKinwUmV+DJdfBBO+O+ATp0c 2V/P6wz40mAKuXmfDlHA3ozHAl9MRkf96kPqtXo1HGw4WeerNa6qeW/Rn+3yro4s EbxCnntNnJutlowtRU6jhQTzkXw94Eyk+0Q6D0R/uujF70oOx1n2vRhJw/Z+poJW FVuzq0oqrZXB1e68/4oWIb6OaECTfCI1d+d18ZtCggfcyjCwNOtDQMNEBcYUIkkl 4p2nEVcYBnpVWmaTEVWC6B7xFfzOc8mWW2LspVBqW1BcFYzvJCkiuKGqRjTcU6Ml tr/0Hz/QSW/TxB7fcMI14S00r+C8yhTOT5yf3jICv3+LInvt1lL2B16FcyUkoEU= =zovm -----END PGP SIGNATURE-----