This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 09:42:20 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f255bab56096e9df1d5d9423e1c0ea57c0deeebc * md5sum 035b5b71b18ff0802d95c72f4cb34625 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXl9zAAoJEIXCXpWhbrlNQWcH/3GBer3bzvpzPCy9zh0lF1+a hJkjlW+VGbqUWOxiEjl8t+l1P4G+QKPI8xmSt96esc2d9nCKgj8hjMueh/TN2eke Jwd89AA7s2XQ+X8hBRC/MdqVDmOXMpGpNGfL8IBC/1HO9qWCTYQqbZjQCHbZ8Hr5 6BxEp/WRFGkSznvah0P/NuB937q35KZq5W2nnhiyHqinvekgyA4qu0j5ucwZHM3f rB9howTVly3d0CWYnLzkMxJsqC9uyZ262SZMU+BauM21+WAqKRXNyn5oEgzOfucd 9XOm7W2vC7uXrB16ZmiZ5VgDuozJuKMVPm7LcSiHGDxWIyfHMcB/e4I0kpmW3IQ= =y93f -----END PGP SIGNATURE-----