This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ezpublish-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 21:25:15 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 2ce89fb2cb56521969ba390235edc75007b7c00c * md5sum 0feff9d7706d4160d02bb29f5ae94161 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrlsvAAoJEIXCXpWhbrlNVlcIAOCVdx6V4HfiKzWMywFvIkK9 eDTudlSJep32M0Fj3DX8DXMqn6x2uM6imH7DtP5orJgyVLBSyczdmRhlJcPM4A57 6i7T7L0Z7oMocgeFx6wiA930x87oRdlU16ZpPUjYGqKn1LcfDxnZ0Ddmca8GH8AK ft/TT4gRgZ684rZZdP031xxREWeK70xrSqq0FgIuJjT4X8e+2bJ8Atz++noM06C9 YPgeaHU4WyrhYeCgsvDBs7lPDciI8i4MU1AeLgvz9TRd+GBSM8KZ5dndsNPvnOb7 xYMjPIHD8MYMDIHEWhAhVQWoyXrPJbgsUMRuqFL7tOJ+26oBR75ymPTseQz2ZYM= =VFC+ -----END PGP SIGNATURE-----