This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-orangehrm_13.0-1_i386.tar.gz.sig gpg: Signature made Tue Oct 15 17:36:23 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum aee4d8606a2dfb5be1d4445a272d04b76b8dbe1f * md5sum 8aeffeb89377ab07397c07d97f000795 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXX0QAAoJEIXCXpWhbrlNtA4IAJKVRrtOjdMIWK3OllarCi6Q FuXBva6Vq3tY6xXM3OJjJri9BRi6ckok5iZbKOo4GfiPfO8sGwfR6v3SIObvwdPD zMnaqCDACHaiEPa/XrMPAeQthmcxQ/DdpOUvrOL9nCryFWuiQ/s4Xke0JMC9GG6E uESWUbUReVvyxl0+vmuOoDGVdi52KSrTo3a1nByqN5W5MGIBDssqjQqkrrtc8Yjp NG3CE4iuHLPn+Ezwz1cVIi7pjTmUzg/yhdtyWsGk7MykainNgEJaKA2YSz7UTPpj kE/IhXOOfmUcTmQ8amJRa6G263PdfX2oCVBO3afpu2iuZt//1ckiAF2c6kvXuTw= =Wm4z -----END PGP SIGNATURE-----