This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-projectpier-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 18:15:33 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e3991a27991115c226306efa98bd5657b03d07af * md5sum b7ac1a3876de72594ab8bc60d6818296 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXYY7AAoJEIXCXpWhbrlN6EoH/AwV6OXYU7WWBpoxpTRFEudy XJq7jwC5rkSiiYvXbXR9AOoWMFjG7wPKooZq12KEQF5kChHJJnZKFNCo2WmOmct8 cGnQxrL0TQ5FD5fwtxq4iNFYxDTG8iDkwIMPkB1HV9cSRZauYXf2chGM450m2NGw DNDhRcuxB4eCcJ8PYgyGt9WfnFSIVUXh8PgpCYiKKgld1WZUjJGy7lzkK9OghPUM NYXyyLTcZ42l8AfG2hx/M8MFa4NarGHdc98unm6WkuPpi6Gu5kalBf5gQw5xJywE 2MHt2XxIj+tyD4/HTeVR7QL1rjf6neyqrdXO3/4F8YRXBkdh+C2wk7zmdZeSOQE= =DiJW -----END PGP SIGNATURE-----