This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-openldap-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 14:44:10 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5a4fc2304cbebafc0f44183bebb2349c932b520e * md5sum bf7421c0cdc8f9d270beda0bf6560388 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrf00AAoJEIXCXpWhbrlNwdQIAK9h4QMgTPLkNkgXRV1Tc9SC ZozyLT616RDJYDa0R/MBYdTGrcjl7usI3E1GfHggzLADQTtvaQgC5wGI30XsNcCZ Ytmkbj4tze0im+wC6wWcu98j/JMkXuIyX/sU47t7sz5ZAePOeImgzVWkjnDmqCfZ nY0KHkiYaaNWod1T6/TlxrLgQxRJQoW2Haai3+gohR3pjqgGm2EgPrrOL7qP8zOB 3Se75xTTLKk0Bgm/E0u+fSymOkkiHUvp/OtZwHBXEEL9WDa8XVANgDqtKlP6Y1Y6 Xs3E4OGV2Pjb1Fh7BwUZGp0S5ClwWcEy45BZXUxmITR6AihQMZK7/BYT6+xo8Fs= =w+LY -----END PGP SIGNATURE-----