This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-roundup-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:25:36 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum c62cd83d85a9959c70849421e976a272acfa7b1d * md5sum 97bd04a1887961122227252550be57de You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM34zAAoJEIXCXpWhbrlNSvkH/109s05cLP8UNDIz8qnnVJd+ x7ibW6eBmrMvd2nB8EHIguRZj0I58S/vEAWws4FOKvf/itfdwXSOzU5E3jPtKo6k AJLkcTgC0Crg9tJTKrgv+j0soT3cLo6NCCwOB18a6nDNk6Ydg4Lg+TuvqhhjwECb fTAle8m/eTWohAoHCGpWy7eKP02LXOcMM8BkB8zt+Nv6VqcNWSnFN4qsKH+NW1b0 P8yOEDnOOS302jTmYh0ZlUi0MhSTXzae0vc6jHcDENLWow7uHgeFMwV9pmsj5aVa Nw2Rdo8EVqHDgutDd/u97PgH6nqu3lUJtAFxjAyu/kAS4AEGtv1ttQy1rin9Tyc= =9JlI -----END PGP SIGNATURE-----