This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-osqa-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:07:33 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum e307f035cad4742fcfe7ad60e72515881d87ba1b * md5sum fcabc34133982386e82ee468275336cb You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3n5AAoJEIXCXpWhbrlNoCQH/RDVMvmakNu2r5NSB1KkImAl LtSGpoSu1r0wOZQz+R4kF80WVj0HAsYQ5K9e8ZWOHstVqu93mCwbZzTTv/Mj1gf8 F56k4/t+qMgK+HvQ0OSjhZS7wB72M1T2NPyQjJ0xi07PVA1RA5GSSaHcMahojUEo BJ8DBQiJacSXhz+u08VCcaAJ3XFYggFBjaRW2qwHq2lTs1h2xtA1PHtBnwKN1xr4 e05yZtRvn+2sedPNZhI9DIyxwKvVbR+On/ugI0SMqGimfthXaFMXKrlyQJpNxX2r DEiDXUL2MdYY8b9vDojhpDSV38ItqqWa96h6uLCj4MzEkdUxsGvjU1g00NXdkJQ= =sue+ -----END PGP SIGNATURE-----