This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tracks-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 19:48:57 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 44a94a019361c90f0317d0e61771890a5ea0b6ee * md5sum e43f9a5a4c32ef605276e4fcbd2628a2 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZwWAAoJEIXCXpWhbrlN7SQH/0V3umFcaaTq0czyKSR2wy3W vmtk/lLnUP1AsGznp5lhtZJjefFrpz4/M2TGM9EYWa3j8Xtb4XHuvSBrOkYUeOfe lWh713xm0uesA1OMjrqASZ+pZLQJizNLuxNCgAmgp4MR9Glix3i81bAHqewQusy2 QpUHDdsB/icASlMNFRwv6MKg6Kv8XQ1/2zVkMNd+rrSHnPxPlJ4PS0cS1+I9BBVR 8/Iu6r/USmEloavmWr2iR0+kyXELs1UA2kv1ad6mlxlwBfMZXQRFZ1kZpu7cJq+z Qs9kbJJbqviRaOZfIqw/h/Z9TEoYJ2l8FUroj8aMHjwJiZ2PyK0PAdtDJibM3LE= =8+2r -----END PGP SIGNATURE-----