This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phplist-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 23:26:44 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 26fbdbaf2c6f2290b7c8b4afa64bd8aa6ddbfca0 * md5sum 90150ab58f452d4e73dbe5ce860c9f87 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnepAAoJEIXCXpWhbrlNT0UH/RbOITo8RVjkItB5pKrf3/zX Dndo1MtRO+N/vUPJFOK3otmwi7nGsib/Fseii3GPDYhmlX98sUAZWyq+1tulhP3/ i4pIyi0KsxY8UWm4wZpVbuQ9EtIGYP2jhp+nLz6bX5G3p7g6k9seQkZ1jqgMGa1C vTPBlg+3bPSTTm1rSY4BhvCor9CT4F1whIWi2H8V12W6xn6W28rB3VdxLYGsrOcH wXdwPnfHkHVEwpWdLXhyCwZhiz47rFofOz5EGhIrAAWeq4NhB4BW86G75u5DevTo 5iIPZrP2Xw/aDcBni/o9Ul/PD8bVv1KpAQCQuKb3/wPLXewGgElsNxgTb/ADQjI= =vr+a -----END PGP SIGNATURE-----