This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-piwik-13.0-wheezy-amd64.iso.sig gpg: Signature made Tue Oct 15 16:08:56 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 25331c2446f1795f9a258678ba962f58a9d96cdb * md5sum ffcee9f24b34cd381ed2748a1b5e2f83 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWiOAAoJEIXCXpWhbrlNP2gH/3oAEKkzODxa77cyHFlmr80k RmlaBGa3gvRf6BY+stREhGXRx1YP+ydxpiF0W44BMN/OdJsIUuRIeGYa/FwhElXa Ir8pzwl6CsE53W8cTwDETcvnNghbBzs61LupcQg6vUAa6y2MduPIq7PHmW5KuQ5z jelUCsgSTnKrTXAQ7nv70B6HoTK/6HgonBl7u4MAGxXxgfAb2VRm7mbCi3mOWnso 8PJKjuKUz+2R2BQNGJ89k8Dd4G1tNhpLzRyNoklJR9OYGxbvmQt8hYA5o8r4lOyp RvqbZzHJzNRjbEDRz3TuEMyCqBM4rUBZ/bQA79E3dxsJe181bj+5XncIOTEt+78= =+A5P -----END PGP SIGNATURE-----