This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-nginx-php-fastcgi_12.1-1_i386.tar.gz.sig gpg: Signature made Tue Jun 4 22:29:26 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ebef198226db31cf6b1e3745493413571483e55d * md5sum d10ba94ccf0262eb9db82ae2c37579c7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmo+AAoJEIXCXpWhbrlNcIwIAKyYIsINZpDkkfL0fmGr3SkB XtTliJIOJX2VPnw82Bgd+eJ+huGNRVmdbmpvVCIM21BazIWejG5Jog4QzzD1IfBK J3yieYIH/5Lv7n9yZDQ4hGYKdgihw9GkfbK/4k7OVcpod3pDLvXeF3xOiQnKVkNW SsRtm2vjI0KohXopjqN0dRqkkCxgcXXc5VKVP5b/AJ4/1Qke5rAtKMf/0NnWRGJr stib/2M4DouG9l1Bbn+lGngwE12ykox06wVgJ6zuWixghEGwI56pKI3KzuYSklAD Amettvz25zu2CzEs0aGfb5qiq9ggz0VSJI88v10pewD/AWnhVlpj6Qxaezfq+iQ= =hmp5 -----END PGP SIGNATURE-----