This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-xoops-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 01:43:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 44682e5c30021099ccf0f58784f2752f96bce4e1 * md5sum 3f77ad1141648378f82324fa9bb198a9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrpesAAoJEIXCXpWhbrlN6ZYIANk5Tnxxzr3ZTnkimVHLe1Q+ MEOnZhArGVAVQLXpLxZG+jlz2Mc7gRc554bDnrBe1i8JSeGewB+IJAISg7VMOKIY 7HZ4M+tFJokIHjK2ZjfsDs73aJ62XdAx7ip6ePYV/gBQSVntOMqvljHCZ1E0vG0Z i4rjAe50RxRrhnTItqOqaHwG5RHvWTBcDgIUyZqfg/ZVeyVW2jJKwyPiHxqJhVxf I+7w/xGY+P2uYLwo73iTod6cRcvD9GNBRDqrJ71YwXXiE5+QBr8nSAov9Ui1l89i QsNHdQ07nu2Kx5650zlIrSlyTsisNOlLyFPiQlItm03XnujToKPcLRSISMCReMk= =q+mr -----END PGP SIGNATURE-----