This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Wed Jun 5 01:22:52 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum eae050534f5b4f83a7f9639619c4432eb5f6706f * md5sum e38eae151a07b9a99b7f35535efcee9c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrpLfAAoJEIXCXpWhbrlNC5cIAIozjaj2HxsQCX2n3BKppwKd wz2/qb0wG/is3aqrnpE4GKqLoEeoqHRRPWx3STgKtL663+N+B4QdW4MHOOnG+zVJ 7RayicGGNEnoSrZ7v9pKYnfxIypXIe0LsVVnnI+uzPz8DzcpeBfuPcf0HTFPpNGc LGNcDKwK8VW9Xs2P8KtW+M9crZiJAp97ca003lIHw6pYzJrYpA47s0i0fbqVsxnH kVGREcbl0S1nGpMiIKKiJA8lw7JyWCHpnZvINbDORGbCVKqNCDHucE7NxQkRGQ4H Npl1Y5nWpl4Ji/MoM1VaaPo1L5nDpziuloBtjjQ8lBYPi+Z8Ei7AiukxWjMd8HQ= =X+5W -----END PGP SIGNATURE-----