This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 23:45:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b5f8dda112c12d0ad1bf64bca2d3fe850bab5cd0 * md5sum bbdd949c3adc8d108c643b01635d3f6e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnwYAAoJEIXCXpWhbrlNrAgIAMZT2UUk7RjO+ZhIwIPuqzHX XgY2pFtryBm/9MxP+wr9AU4mSbBb9K+dZWgViFCAypJXP30xsGhfzT0JEbYJWFEh DJey1phNuhyWfYeFzQ5UeMHy0qJ35ZtFL+MVT7+YJWe/CtK6vAY0WhGOJKU7ZfPm 7qbfeOFg8TF5FRdF34VfGfEQKaoQRbLHu4+KDyPXHQdT8let82Faf6V1Nz5Q+QJ2 DVQWZkbMYZwzQbHUzUKLwfl1RuQiO4IflGnRNdsOfHlwFE6nbxBIohwI+qDHBnTk Lgg6/AgV8vF8UyCZKsV9pmFOjut1TF8JwkggDf+i8u0WDuY3fp+LQA0DARQsp4g= =COAG -----END PGP SIGNATURE-----