This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-nginx-php-fastcgi-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 14:33:37 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 1c68de38ef61b8d57f93fa6572bbc1103f4f4d69 * md5sum 419841e1ecedbaf4ae1619896488319c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrfq5AAoJEIXCXpWhbrlNiJQIANic8Kb1KZvWi9f4hL9RJwNq inlRGzkdL4DIj5UDKgYKHc21Kex2pOaFFkaD9Nq2O12bwkdPk07QvC9kvcE+JxsR lJnimk4a75hvfovW4AWeHD5dSN5ouqQxaE74OamnnVLWheQ4Md5rBchnOJS4+AFk FjU/vz4Bv7Vr23Uixwoi0jOs5+Vm58mBshCl+X8ekCPrApp221oCpKl/OamZjeSJ vNutERP1UeAkIWpsVYFmLjP0NS5RrqAAnuhQHw8SPHMpfNaqyAYCmDiOJhtCwIqg JLtD6S4enCmzRItKjbSnwXtn2YkHcfVBHaa0rM7ZGAVd48uvluDC1ylCBCUxgDo= =T9qk -----END PGP SIGNATURE-----