This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Wed Jun 5 01:09:15 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum a88d3359a3010934848c8e9199f55798c184708a * md5sum 053c8058ab862b072b41517644a9a09e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRro+vAAoJEIXCXpWhbrlNLVMIAMp6+VW/VN7TXug12dv0Rcqc MBQzguRq8KuiBtWJtPdd1bCkAvI/8eY5yVDZg8b5WAU+FJOi+ioaKpTI+Wj2dFnI TxI/bH3Xh3wi8tUI80Ujb08eMTjtAKc3x3OQRmpV6EiBXHMX4tjcJJFBUPfwMF4v HlY7VWjevXx1O8J/pABPxCFdJXY1Z6kRoNhoXnKy55ciEOs0XgiJfc9w72hiorFI T/itKmDFcugw9fRTNBq6FbeffPY167evCffxkd2W0R7qDhufrzUecTPUnZ9lTXL2 K/ZthhapQqGVijOskIzc/ItVQWA7n0s9WzXQgcwOy9Mc73lR2cMgMZBjerRq1zg= =C/t+ -----END PGP SIGNATURE-----