This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appflower-12.1-squeeze-i386.iso.sig gpg: Signature made Thu Apr 18 13:19:02 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 79f60342dc14c1435143f66a95a2cef90850bd08 * md5sum a6ce1f300323af2675a540a12eab18ec You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRb/KuAAoJEIXCXpWhbrlNu+4H/3sBB+Lw18HdWMs5E2fYWLW2 3E8lRuDr9xQhVpVzYXmFGTGe5I43Yeg48EfL8EKeVE2moA+3uT7t4sReo+M7VSwf 6GjLnJbJSDjGrjuSnbs2WSBod6B8ROtVnoy0U+JctwGmzsBWxenMNmIY0XK7BJS5 C0s5DBhIhqgGqNURUIofa/IzrKDxDCic8MK3dOGk9yZuwFFWTC/jriyMEjwc5Pot N6enDjNaGOXOj3QLWweXV1q6Nai4jha9oROLpOeK3snM9fKnbuwVm7GOY1oDp2aR geZTg8ii6sYm3oSapTv6k8hBHUh4O5+fTtT77T3lqjMpRYmVSNyPy2H9bTFAQwk= =VkFH -----END PGP SIGNATURE-----