This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phreedom-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 09:25:22 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 6f1ba819308c0ee59dc23ec939baba4440240d2f * md5sum 2291212e364087fc51132f877deef5d9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc3N7AAoJEIXCXpWhbrlNTvcH/RIiYQpANgdWT2aIvSxxmOWL 04BZaaGLxb7DRApDb98h2poo+DmweW2kA/K/zfrtUG2X4XKFWqA5MUJKKu3IoOia UrRmxPRR/UR3d59cXum5aNc7BbMuqcLO1Zo801kn1d28c3KjZ1FnFwEnq3LDhpy7 STyxE6tuOtFvKfDW/8/B2admvnVuXYisbR9B7knatlew7SCEnQCcM2gIsxg18J/V 3kNCZcMuegUVT+EQHDLSh4zrFqN1G/14WFT3FRD01io2eDP7XILibCe0q3PgTZRu RWTe0zmEFW6LrbicDiQccXCwoHcX+Z2R6F3oWCi4JigLFEO6S/gXTBHSWxvM4Zw= =XR3u -----END PGP SIGNATURE-----