This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mediawiki-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 21:58:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f413fb9c598fac59f20975dea6bec58f82a54f1f * md5sum 8012430114559d3ff0ec880dedccf4b9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmLtAAoJEIXCXpWhbrlNnTwH/0KZc4/TS6J5EJwN15uUmSoe Ku9RWxwQtrE5kd+bK+QubZnvrBRg1nRryxgyxOr/UB95aTos43r0/O8bE7cnViUt g+EpVkoMToBamwb6oXjOQKOqcfWN2vKHtS9MWdlc83u3FG/hN6SX7APWGlAcGuVo 7o4e8Os0GrUoWfHRBEd8bKI8PmNoj9uhdYIc/Jef1BH9YJq+arjVQWP2lNbPhpNY XA3Ohmw7xZvGj2pMOviiAksp5R/QjaMMBXUzHsSq6uXrYJZKrRDIWO+PboGU5oDz RJBBj+MQlCaUTqo6i2HNWhc6nhpw52RUNTksJmgspeQiT74fVkLA4qzZ25G/QEc= =M0qU -----END PGP SIGNATURE-----