This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-13.0rc2-wheezy-amd64.iso.sig gpg: Signature made Wed Aug 7 09:25:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 85d2fcc352d4fbfaa64062ad1d3b09dc604eee83 * md5sum 162a79d7179480a15a07d7ff8c2502b6 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSAhJwAAoJEIXCXpWhbrlNkOAH/1aMjNngpe1jDiKfrFehz9BO 4GUG/vrTXkPwgVT2DyY0bfd7ZEjdQH8xcvX/ktV86kkbpENFysTxgd5Kr0GdKvZ1 EDqNI4K5vdFb5ZWrdBT6gAu6m5u76r3/as5lTYeQBCvLUFgdynn8XHuYC/b59MDs 7+cewe+iW7yZ6FNa/4pRm9T9+Se/mgbAd14DxvtqaTrOvf+LAtDFOpI8S/LOPhYa fOqXlLR+Tfaob2LqTypkExuW0NVd3vTsfqyJrr21P0RCaFIae8HE/MX4Gzg6OTxV Y7znZWKavFHwRECUh4qjGXkBf+i+b+8rKgxX5gReUvODqt9uatmZeq34PvEz4UE= =cBop -----END PGP SIGNATURE-----