This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-orangehrm-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 17:31:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 3eb9d237edecd070fda87e97e8f33a8b5b1a1c80 * md5sum dd11a78b5d46ed0df500a0db2ef0832d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXvYAAoJEIXCXpWhbrlN8i8H/3vLLn4mQuGTB24SXR+kQACu mgiHXMuWS0qc6y/f+sNGArjXO15+ADQ2mUopft81aswYipS81JbdCYz2JNFkPziZ Cw6WoRaH4SabdvlFZyEtyxtJYdPc9s+dFpNZHUJoy3cJEmcpt1yfGYUxEyYJwY8/ sqAl1ZO5e3aU/bh50BjYCHJbR+CUwsBPjG7E5kTfWObDDSCzdEHuAWtpPN5+j3fQ oDyPs0AMVaAR0rhyTx7w2jS+45UAqCh0jGuPnXXTBFkMlSsbciolanLhOU3s10De U62aaUvbHhCHuU5C8E1EWcshPFRwxz+hWkmPq4BaAc5o0HttLuW+0IwqSp4/YjA= =Cp7D -----END PGP SIGNATURE-----