This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-redmine-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 23:54:18 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 377908531c0ee7581180e91b7a22883d8319f7e3 * md5sum 00bb75107d91d8f072ff31f3a3f32077 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrn4aAAoJEIXCXpWhbrlNoTYH/RlcX5Z8sC5H80oN4RZlryVh AgRE7YaMksVRXdAXOI+J5nAdWSHVzfsp84IKx63M5YDLNBc8m2nhBXo9wuMatslo 144UiNEstNRj/JZnGIuxNuo/b4Tt2dfEuxQtGOZxa+USQM/MswZxeEBXF0M39RxM +PmyTqmkWkRS+Puv/FyeShf82SJ1nuEZqvWCrJZcyclX4S0CPrOggjiKKPDxzX6w LpRrmP+qatAd+TbJRgjxRtqV8SBeMYONQIF3cQECwK2LRL56aUqQ6bxrAN8AOc8p 8gC8PlbS1KGJiaGH/xREC733p8IxbD3icvUqyvgBzxP5bs18xRw//L5rP+Pg7Sk= =ZcDT -----END PGP SIGNATURE-----