This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gitlab-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 21:45:35 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c3a925a4231cdbaccf6194f181182cf022354e6c * md5sum 5f24e6b0039f4010f68446aeaf70374d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrl/sAAoJEIXCXpWhbrlNrKUIAMn8gmnLMj/4GXLNIr1vLTxV +G/JYbYcm5Nbz2GtZKeA51Uv+Ta52UoMfWINRMk7riy6QJ/1IDpL0eSjt4CvOTdu Gqv5f4W/ZCs/ZNV/V7hchKvBokYaGtqONSvwuNzA7Ec0AwP6ULXvLDxLOyeF3kGT 0XnnfZ4dzO7kspk1MqUpPE+RLPQ96hVaKXbXuYMpRmTURqPgkau95Cx8hXGWcM2z GYlHVZvgXqaoiVh/p7pOSGmEv39d0vRd5alAFjcQOlbVZ07WVG5SDBKVznINH4dp Ma033Gs2+mBQVLgOUpXrqptixNvtBEixBEzCQ5o7EWNtQgMpNwBCCMccp22RtaQ= =pIaN -----END PGP SIGNATURE-----