This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-typo3-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 17:02:11 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 4dc8d5f81c23b9c934bdd32bc51940c968048e5a * md5sum a8dc221a72756e9b61fa5f9c6b6ee65d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM78GAAoJEIXCXpWhbrlNRbkH/2QAcyPl62qjTTMz32IpPBwL 4fD+tVSWK3+u8ofJMjCUuMFnzCtsMNOcClXObhAxzaD9Cy4Da4QJQO7eX1RKuPhC thM292p+2US46bi1EQp++zYP8adED1Esw8mmZk8mn8AJRazy4O5lvm2cTB3UiMpi W46+dKrnmoanhLpL9GbbiJ8FRKNeRLlfTf43E/pxX655WJ+r1yoGyUE+av9E3USi DB1dSSEB1BUVEXegAW5yg6xUu3u5/uaAlEBoldRXwKW8+1B9uLA5IldrOON+3WkE QsKvf1S+Htn7eoRPii0pnZCThlS3kAARHeCcbA6H48mQHSvhkDVfglUrjNkMpjc= =8qW0 -----END PGP SIGNATURE-----