This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mambo-13.0-wheezy-i386-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 09:17:35 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 481ea482bfcc73d97677dc7b3f2c2443d3474c51 * md5sum f0f732638a184f007418d3c51801fa41 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc3GnAAoJEIXCXpWhbrlNuPkH/jhSIPW706CQp8zDiDN6SM9a VKZqWXiX51zj+MP8ce/JuDdvw18T6qVRrWjrtOAP+KpDSHOWWgKs36j4WmZmaspK v3Std4I+INxgxVOvc6IzAdEj+KwmR+k4Ysb5t+zQG9yPVNCh0+c8wfAB5w7wH3ms KYDQu3n60T9p6Z4v9gqKz1Olb3EvEh8WizEmaCSRadGgEbkC1yU6hTkkmwlpAowK wgwOoZ+fXPdY90kIxyaSB6UEc8j0uC7FQB9cNMLbO/O+HvUVlIpyCigYvxuTrMep ueabg8psAhby5NHPqdLlxcX8ru61QBhseZ3pFMouTsab0nc2Sukri6P++zJH0c0= =MSLu -----END PGP SIGNATURE-----