This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-orangehrm_12.1-1_amd64.tar.gz.sig gpg: Signature made Tue Jun 4 14:55:18 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 6b17f6c47afff3d7ee2f0821ce6654e3ddf307f5 * md5sum ace4d5cc6dc894d60b25628e25135fea You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrf/QAAoJEIXCXpWhbrlNaMwH/1vy352u8e8gzDeKB5NVxraV 6vXUXZYGGSref82nFTaitO+Qo5pk9MjPLNQ/u4o2hNufORLAXO8CCaKHhchrXFCj mpctGu2dyIU3rJT/MH2fRd9vZOq9g8qJwpX91ZMsQFPElh0NDExgZ3VITtlY7wVJ TEu4fsyIhXAOc/zL2IZpYTCXFbG5eCUe56e2x9TITufNdXkeTdjT4tKW+Co+o9zF PbZ2kp4uyza09LbTCLQMS9X2F4vkoT5pL90y17FWT2Q5Fh6J7gBK/qibYuPjgs8m O6JHQhhNKfRzokuNSfOTCl+caglYiV2BgwO2ownIHcjA7Rvo6GcsGZxHieR4mUs= =M/12 -----END PGP SIGNATURE-----