This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-sitracker-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 10:20:49 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 7afeeccc4a064ed1e8dca83137b7f553682cdfd5 * md5sum 154f90b61f2273178da120bf51ec0af0 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXmh4AAoJEIXCXpWhbrlNHWAH+gKMVt7CPgewM9TfkTcuzSlj s+Zg+DCyh0aeBq/p9WI2vEUqwHG9HgS1/cGVg8x+evZP2vDPcBEp1Hl5OQmlM/9O V0LazWX6Q5yRNZjVhiEHx26ObVd/5mvK969kIyzaxfk7nscNY5stsRTH/bGrA6c2 j2g3try/eopHwH4nnL0LznPen2HHl5N67jujO0DqYVt2cpCVi6jnMtO1VulkJPCf QwqLBJr6lT3/2r5eSN57v+zCrf7hZ9dDUzwVMh95uH99FW+64oLraLrXPe8RLuiy suFnhcFlFPA6TW181tXR14zQOCe/jomFuJuBpEBRqdaRR69lx3NLN5MKQxMffdc= =cm6I -----END PGP SIGNATURE-----