This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 19:31:52 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e555ee9a6086e7425345f2ce67df5b89c07596a0 * md5sum e8c2ae4a818a39cdb5a82f90408ff174 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZgaAAoJEIXCXpWhbrlNc/MH/3uITAslJbQe1vzaP9L0Tg9c XBcrwhEeg2U4K5B83a/v5PUVqFd7+oG28T3xfKJykDEKyIZPJwTC8sU/pVR5IpsS 2j3dgqImwuXXV2EKW1vNu5o28GZolf2fpz2P7aaix7yUgqTxEX/z3QZKurrePFiF 5yiErn0VyNBDxV6/3mzUTs6r4dzaYhXl0tOpCDwFWQO0757pCwbzZI3UpbDjGbZj JGOwiZ4Zw1K/GNY+QGQSt0wdfsfA6AEFQdN6uB/Q+r49KKB58RtEn/kmfTdpulK1 aWNORdzjBP0ZkbAvP9KVAFu8whDBdzZMDdN3WZ0Y1k4UXWLMfap1ndoX1U4h27U= =cCgA -----END PGP SIGNATURE-----