This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phreedom-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 17:44:57 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 914e251ed56e7544c9637988e7dbeee29c9263a5 * md5sum 917d9744a6482aeaae787ed7a5e4f0c7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXX8PAAoJEIXCXpWhbrlNMUwIANfEo8DUXaTq3TXvVnigjF7K hm2bOUJGToiqQ6QcBo8XCfKzi7tuarkmeHTo/mkZpzy821KzNFjdpv+4K5nXTZYr cHSwhZMTY3CBlcp56ZzYHIwjkhaSPxzpJA5ekIOc2sDIAKgfBp5L5GihO2wkGkKg dsrjy60jXhYEYja12V5hhCoRHJK8A0tpXO1TNG6NxXWPKNO6Z34xM3PAuRWmYqmW Nu8ITGVvw3Nejkajar9jhbAn1o1mHBa/iv8LykiyPqzFEZ1hMtux4FMiS0L8B/SM PO3JWlaS0b8w7VtHey2ZR5lcV0NOZv4nOv9uPr4SzFUsEoB12KDBFJEDAJrw3Ps= =FRL+ -----END PGP SIGNATURE-----