This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-piwik-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 09:56:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c7ab717e861cec8f9c8c4995c207f9ad72b92f57 * md5sum f65850899f09876a28ee1e640d4807fd You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXmLUAAoJEIXCXpWhbrlNvpMH/AmFtR42yrbr9cxn8yPGiIwO 7K9C8irl6OYiJYJP4ddtCJ52/SmHJHDch7i47bnk1aiuAXu2tQ7wPZfNsB9R+tSe pJflxg4VQ4fRCNJGcsb9KsTK3zIM1D0SJpOAc5ITCxDC+e3OSnMYn944Fcgdnato 9erAgRmqL7B1Vqkbu3HELJjljW0sLfOuM5zdlXEuxNXOFv67WNfb8lajnVESb6rl 2b1gJXLECNBBl406J1auru0YM1Nret+0Br0+n9PvThbDHdjVKFoigwxVXh2My7Hj RGFkWolEd48j3V5gwtEG+vX/ZXcG9rAkIv85dbxipjgtpLkAJvJtticOtOT68QI= =EL21 -----END PGP SIGNATURE-----