This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-redmine-13.0-wheezy-amd64.iso.sig gpg: Signature made Tue Oct 15 16:42:04 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8435f3716ee649060ce800066583752d80bf0346 * md5sum 1463f4411073eb3c27bab32c25dfa81b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXBPAAoJEIXCXpWhbrlNl7gH/jtWqZMrP2Zm8TMjBmk/mIci D8e2I3dCTChTYlOb4fDc1docFDNylV79wbE7yoDO9FCO/pUdlMEScyj+m6msVjKK /OY8BBniMUbOjf7VZ8IZxpB2nrxBebqmLVKiJfX1SMCMEoLQ7pKZOs66pqEq4h2r ipTzHAccC8aD3G3JB0EuAZ91YIn5Dyar6rav+PfOziQth899MbxyUUnKovx1fy8z DPJ73J20DPkeaqtDaMX1CtsFd/xggP4v4Qvojctx+bjO2rttrtuh0SyFpZbKIabr 9mYaBplecPiU8r7D/sBgc33XubyOTMosMwGMQyOPMU6waDjnGiyAOzjLgIX/c9E= =ouDG -----END PGP SIGNATURE-----