This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-piwik-12.1-squeeze-amd64-ovf.zip.sig gpg: Signature made Tue Jun 4 15:19:42 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8ad359a6305d3428dbc732624c3ef7fb69cb98ee * md5sum bb9d6045a50c43df6489a40b45fde74a You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrgWFAAoJEIXCXpWhbrlN5gcH/2w9d4I0X6D/WrJsJD3ZzUQv dtIh/xzdfmqNx6Ma2Ig12WKeGXBoIrcmLbY/VenrA2IKbVFnIvJZfor1jD53ww/K 4CybhbWzqxxrlg0m2w2gNnX6Prjz1ncLz2DLdPo6xqbUa/1Wt4t/+15WKpiKtIc3 ZvCuQ5ArvvJ0c4ZSaZDbdxNUkS2qrZocPIph0yK6FFhxiGcamiouHXZjcZSz1y+R K6klY9siQlFmZSBXopnFuYbGt499z70kqfid3k02X08hX3uckS+N5F7AHT+wW7EK VO9MWFsvVQJVL040YDVgBgcYXXL7xDgWdYogbHyp9wnAsWnOUt5nWTmMCQOmb0o= =Kw4W -----END PGP SIGNATURE-----