This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-cakephp_12.1-1_i386.tar.gz.sig gpg: Signature made Tue Jun 4 19:51:58 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 670c268dc5d06860c624de4cefca69215dfe743f * md5sum a7db9d53bb6376c73c35c4c6074e7ad2 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkVVAAoJEIXCXpWhbrlNvDsIAKOlAOefpvf5veM3VaYj/ncX xORYCMkIIHvvl1wxsMmratt1WgMAKUSxMfcPmheRmEAiUXW1UTgpSjzjx//Jc+m4 xotRA7RWF5KkV3WmW3fFEKiDOk5GR8qUWzOHUPlmvI173BFC7bDo5f7ML0/FX2sr t6uUZFxu2uZPjfosSRqAUN4R/VjEcB+GcbgYdlSj8GL8pLFM7u6zcAa1JOu2NNfD +DmVQ4Vt2TFarTX6ldck7aoNaFT+7qp13xpxW4ORGyFmIRMzVU112fMnTWvy7sKs 89h9MK/1AVN+gJIrat8+wLNfLEFr3HxmBzOS84Y+NfrhNo/ETTJjtg0vEChzcfQ= =p8Yl -----END PGP SIGNATURE-----