This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 01:10:06 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ca883ed7275aad63bcf4039c47ce84cdbe7a235a * md5sum 9f5909d3ccf22fa1eedd188a931c037e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRro/gAAoJEIXCXpWhbrlNhNEIAMIuoBbAuFCKXmBapoCBqahZ GzXAXuTk0OkZNQIijVg3hsGfy8QLmyk3ohzzRpjkK0yG1O4PSrrGJgJYsl7MHMZP rXUVRJ/eAEh2fgTPlQa1xKJBRMwmEhZLid3HMcorDbr4CSYk71VY7hfT25PV/l4d n1s8lmyljvkHRObG3ILLFUphSiE7duKpk2ZOG5Dh+iQ1uVI11K2Q2CaGRUO0R2Yn Slc1gWkpDXU2bx9ePANWIFTEWDUBVKa7qL6hczU0yWSN+a4T8/YjdefBnYMd5qRP +HBYttrYL1q0hLZzmKt5bCyRWxTUYEBwLeFEVQFZiWajMFfjRllzlSMM6AbnMis= =ZGmj -----END PGP SIGNATURE-----