This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gitlab-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 21:19:39 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ea91fd874edc9acbdff25f87ab7ec751f7424054 * md5sum 0d791c8f8e3d49bc9ff3ca1d34f690f5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrlnSAAoJEIXCXpWhbrlNE7sH/iISHkodqYbywgCkms1m8Xmm WUrlEH4nvfSi1GSVOahSaE9rK2UANZ3jkYyyqIrLfYU0e18qCQ9R8MUyNoUJwwHT 8LSI4VSqqUe260sMJPt3it6oxOiBrbKaulhEhk/QqkPAm7gEWQvXg+WaZvlVqUsS KKHy4Mhl5vfeaK6xjsVzWbszwmJ9r+/aK+fNNusYsd+RioxcAGUqk2+NxwHUv0WN St6y57XtASlyUrzCOrJyHnvVXXnY1jy564dXjep2sMamy0apjnx1qfgkneUG/bKu oTYUl56oCBaDYhHGdzADpxX5vMXkLtmzNJFY95q73LmHQhqhLHRCm7zYkWSpTyM= =aBdx -----END PGP SIGNATURE-----