This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-tomcat_12.0-1_i386.tar.gz.sig gpg: Signature made Tue Aug 21 14:48:53 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum a38c4180b0e5fd802afecac70ec5780fc34c2b8b * md5sum 703cf5fe6b60003e6e494b3bddd5e315 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM5/KAAoJEIXCXpWhbrlN630H/A0yzjLdzbv8/seojYmGoPB5 0nrZFOq4fPK8mYQN3nsWbduDmp/Wep7f6tdh5sBiX8943CC01LpOVcsXZfDlsnLj mY8oAQW6LPAv3hkya67u6TtS4SfkQYDeDP407erbO2k91XQEY4W4qAuNvzI1j2cw AFJKnsSroQ1ob5kwZVfgsA95xN4YJv5hpnVN5Qbk4Mb8ISx48eD6+mST8kBO3qk3 NOCEC6Mg7rYWBh58mXeHCjWKa+Q3BQkuV93geqe2Mhp3OmMa94qGNN+US/wYHjFC Naq52iBJeqUYXR+mV84ZrqkxYt4b3w8HjkGslozyAW9AMGEhXuv5HaS9FjzgnsU= =5vRk -----END PGP SIGNATURE-----