This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 14:18:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f6b375bb0cdcd79d343bb77bedb3e80066f25d91 * md5sum 0ade9a68e33be54cf8a984e2730ec5c7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrfcfAAoJEIXCXpWhbrlNhlMIAOPzdpgQkJ+Wfa1cRREjX5Fl 302fynIwJh2FmFxLw3s0MuMZMEmDn4g5CQhIxYdFwQgbNQc8XhV4jCEyXO8X17KB zKZUxQtQal39X07HxSfQffR/Jl5yNUoE44qqI+UDO1XE42jytBwTu2KtkpmXDSzH 7jbkHs7Yq1e62Krwo2ABWmujOF8N0q0HNW0zND1ppHUSmtyobtdNp0iN91ilml1u EPCph1aYyHwkLiKaXo1xQJW4qcG2ezAkAuf56kMguBRi8NBiMK3ZKnx+48br8Not ZX7AoNUlw/ufJGxAggKNTJ3MatTlx9/inRVJFlQQ1/gLhDxNhwbuyTdEOStbqdk= =17DR -----END PGP SIGNATURE-----