This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appflower-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 12:38:18 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9964156614c9aa95671da16f9d8932b689c71cd6 * md5sum d2dde84fb4cced003173bb3d22201293 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrd+yAAoJEIXCXpWhbrlNZv0H/iARGsCUM39plkRih23IXKzv JPC3ctofOnTW+5qYIZXLVqFqjjTInYd/5y1j7AOTU2/qMqmyymejpw7ddEg4KRwA jiat394aNlH3hGQkpJpcwcZjvW3V+TI4Cv7mi6+kxrPBIdxJfp3qzH7QVJKaAuve PBItth8foobRtj+Em8r/fOGGsw2JlG2OxjyveXs8FNnQA0Le+AJ0oZG68g6cVaUq uK74GthTmtU0BuMdaYODLbKGbRIz0jay5pGiDe18FWRJkFpq3NOgzpqVD4kIgwcU xr11HMUHgcID83vUZEQLx/vDBRtMyKx6RibMbvtd3hN1mi1ec6MZHWgicnJ1lIs= =j4hY -----END PGP SIGNATURE-----