This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-gitlab_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 16:17:50 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e58a96746c5f87d216e5e7efd85c54d7c3edc5c2 * md5sum 95aa9a8f6ff727bba1d3317e7ab03db4 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWqeAAoJEIXCXpWhbrlNrugH/2KLFqVzDeNeFUVJPOBy5aYp KzcT9StffHHgBh859HLFn/nHcsmw+l4wnZViIR3MnNBS8Rz1vInYL3Hf2uM+ILr4 Suo0p1pkkmViVO+17Mo+pjObnXCJY9+NK1trniaCrpzys8jCYOVp63OVYdjlKZ0h H9ce6P9sO6SP9IUla0GswaKB+w1ZiGvz6yjMjKFubEnnv5aIHEwO9gYMCj8dOO02 KhpIchCn5Gc+ceQyJ8AEi0xj9z3bTqWa+lUKSe+G5KrSKKqzE5bG6rU8Ur8XUnkq aP7JYqJutnTZJkeqTjsOZpzjpB0AjMAFas4Khu4Ck2cBkjCufAMKFtqLe5IQsOg= =1yvV -----END PGP SIGNATURE-----