This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tracks-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 19:48:38 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum fce1baa8019b23be6d97a0a3477147506f8335e4 * md5sum cb52762fa1bb03cfce1bd51e9a63077d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZwFAAoJEIXCXpWhbrlNVz0H/0O2lSaRncUcteZY6Zq//IlV 7qM1Byykk1qqQXUmsOTQB55LffYDEa2c6nKvZ7ItsQLaFPE5VFhfv86DJfw9KGEB iNgEt9ih+Utxs0vJS0rQ8Ql2hqHAApqu+qFeyW+uCHYbcKr7Cqnt9D5KEjgg8na8 xDZR7XnyrMe3VQRWybkyJ+4COIz5nU7UBDLHATypGYY3VAafgq14JRDv9MPfpLFE 6OxNy45Bki6pjlLfLRdHG/dnLVSbEln8/uWWNyLxybJ3fnT5/5tgUcOFd/ESvw6L 9HLAZ/423outGht8xjOvOklHrKdJlU+v01XpRgKq3D6/PsPq7N3CjA5CQ1fGLhI= =V+XM -----END PGP SIGNATURE-----