This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gitlab-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 08:47:55 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum fdc6d38cd0831b00d7b632ea607fe9ccb6aa52b6 * md5sum f3b3069ca87a5afdb7837c97899752b7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlKoAAoJEIXCXpWhbrlNVJ4IAMclu7T5HtSB0u9ohKAqQSlE WCgjn6fbyQoL9VEwTKqGjpleeVOkU5tQdTI2SKOTRFfbgNY6Ze9zpLyizm+dUEwT /195Y+bAADVptx0AnZaHL3tyWD74rYdvywo0fIkxfGuOxw8FUI8U8GAGf8xLYD/B xONPc6UcFvvUM2QRz0yBbK0TmnhURkkmJx2f2zH7ODq7b2E0hJiDGZf3mWXpCj9y CcWftQ40EE6Yg2K4HO1ZoDgwIK2Li3PslTnZ6IvKWd69e7HDOSDQHrEejPVIFr9w /dlkn098bXCVXqt1CK2SIqtb8GA4OpASe83pDhKQ9EKNzkXHoGsD65oFwbP4uJY= =vaYX -----END PGP SIGNATURE-----