This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sitracker-13.0-wheezy-amd64.iso.sig gpg: Signature made Tue Oct 15 16:37:47 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8baeab95e1578da5ab0c2ab0465acc9b258e0d4e * md5sum 87cf4d66a311c3c1f33e9125c62379b6 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXW9UAAoJEIXCXpWhbrlN2/EIAKuUpgGyNJNiNbm2Yg0TuOQi LIZTBKgMbLJ47R9H5VejyAt8jdmwRx8Cg41wrqIusSAREIgvZN4ZlhiNhG5ZCQH2 +0SvEgGtC+hJZKhFt6fNs9G0AxpQxsGksF+6cbxinMIzk9STaoCPJfHqnVnhYq7L 14l+D70/uZy+4m+qSPGo17yqLvkGNnXBbFwu1a4vKhi96tljN/x266M7OmxC48T3 qpbpbeOTPnP+mjH6W+4McbZL0FOo3g8re3eljZZNsba9ODKHp5PY+SPf+g72yczJ JsjG2siw8gKjGlK4C0UG79Quiz0KHmFGDbP39rEWZgEf4/e5pWBz7tasvjPaB1w= =h39I -----END PGP SIGNATURE-----