This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-13.0-wheezy-amd64.iso.sig gpg: Signature made Tue Oct 15 15:33:47 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 60c726a3c14a1ac036b163afd0e557694762e3d8 * md5sum 635a02ef2f91a6c7b73d0f6a58eb15ee You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWBSAAoJEIXCXpWhbrlNlCkIAOwD+S3UkqvBRrYKepiWsr1u 1HYn/0RluCMtXvM3fm0coK4IaEWaR8bGEBJ09C4GVzaMZ2wgMfK6S8/4Ba6JUHVe yC1fBhV+AHxvCht76NXw+OU46qZmw3E7aD0qceT2o3aPxwnBlSiB6ojH2hzqV/M+ 7VwKrC4v2CUwrhuRH/+Pik+N7iX9xTyAPlzV2yojKddFtLC13LaUgJ21B39sNpnz fsMelBxLAC5IaTYvuqg6uiflnSBnHVISnqIckr7KF5ZJK7v1ijes9GkXlj/ZVTZh bIud6R7ZIoWHFSlMwJKISYf/dISqO5aRDd45hAwNuCFFFV7pIwE2Ieo9nFg8v80= =hidh -----END PGP SIGNATURE-----