This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-moodle-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 09:16:31 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f5a0f5b886ee3fb801368dbbee1727187a364e0c * md5sum 0ca1c9cf9bef08891e4c39b6f649bb16 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlljAAoJEIXCXpWhbrlNuywH/R/frf4qB6g5AY9jb/HzbBTc OLykj3H1iXesphCn1F4vLpnmGJW9vhQI5liJdSm+PNa2J9lKsZpudmrcxplqdzvz R6IOWUqexm1F+HXNhjVDYlKt4dZN0qzSJa7l0ISeHn2DTYAqlXzMO+1V6GvAuyBr lFKs/g1BC7CtFbwIFwMoKJGLpry79scHRv1Vq2XmnR0K2UoAmkYefP011RLZUC8C iCFEP4arG5gBMLqIPbqeetap/gMk1468gD0YpjXfQLar5nnN2ZFP4pMtiz8VOg79 AG3/Vk7asglzGz7bRsof0PZa20F0+cIgTrN/pIM34XXxsy5AfXbpx8DOBOv4ZeQ= =mO14 -----END PGP SIGNATURE-----