This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-zencart_13.0-1_amd64.tar.gz.sig gpg: Signature made Wed Oct 16 10:54:36 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f7a80dd22542c000c217fa02cdf3315dc57e96df * md5sum f5a93abc5322f3f4a333be54786c3971 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXnBlAAoJEIXCXpWhbrlNdWkIAORHL0USuIyvy8MIydHdh+ra 3w42QI0lBClU37ClRX3CYJzvjmcNCP40VCyjAnNwp3y3tI5U2ipccn7BgPmpezmk ubwau3PrOlfe3tuCSQIgapmx/ckraTxQ4qOzLIW8VTyMPoSIbHDoBSags+QvIT1O Cei87M8YV95sSYlkPz67oN2h7vVDjC0+IwKO7hRBk8nXKOJXHVOw2xjR1dhx5Nyf Lx7LlOpkwoCRrhQfU1upcBu3ZfuohUvrOgcqzeuflNLe8cjm4kp7OrMNM77MuoOT B71gPt3bRIT8NS1PeAksjPp0ffcBGM5COAe5EdoVP3NbaisvwRD5Cf0qSy597ZM= =dDeu -----END PGP SIGNATURE-----