This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:10:26 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum ab0fc97e6ebb4bcc333b011ee9aeaf5f16785556 * md5sum 793b27f1388609fb187bef2d84c5bd46 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3qkAAoJEIXCXpWhbrlNgzkH+wXGlzu5HA9pG6BDBJD0nrND 9EKl8R5oP2UcEZvoRxEQz280gOERWqUcPJWHrsBw5/s1IQEeWT4MTBr0b8fVvLx5 eVIsVFAEsrzvT79XoxS0pAqB07xiD2KHRqs1QF5eedIk3cD3Rou6mJLzx6UJA7Au FsgqGoDk0BQoHjdkuQjKKQ6lr+M0JJLMSkDIOXbWwEgp9VEdyfl6tCDG2h4QXNiC /fqtdRECgHrNxJG1GsFEzd6U+0TBkO0A1ljqorkJ3CLv2LU+IEDggvXgr8jAuzee L0D0NV1DN+V/Z7sAR/8OkKEJwkPuXKzWK24dteInhTgJAkj2ePInmVBVEBhnqwo= =Obld -----END PGP SIGNATURE-----