This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 18:44:20 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f8626f0bf7effee99382b3514be46c4ad3ef0e04 * md5sum d4f1c8e5af8264bbc43e1173128f4db4 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrjV7AAoJEIXCXpWhbrlNi80IAJDv4udWNOSI24fI/ItzuK5+ wlrrqwRjd9JPKoFSZDEQ1Mh9Rbwwbp15y/ke6t511nve5KYw6t0JaPaB6SH5M3A3 aM+AK4zBthMDfM1n2USBBQ8PQWpYuzerur2qhNHDvM04FXGLh3O5UAeOxbTWMMm5 CtK1bVjV2gTekvgb+RGkaPaG7Uonvgq5Xp5n6/Se+Ia58dyCkYy5hdtiEBswox0k ALOXIS5u3P3qViHu5YKrm9cXwLt2PsZf5fdGvUIezqvJQJBxk9oa4jQMYhUsxG4d QOA6FJcOy92/WQxVdJYhhD1b9oaY0+20SmyIZGRg7PtRVX3XgG9VxTbnt3/5+H4= =4gps -----END PGP SIGNATURE-----