This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tracks-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 12:39:13 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum f4b71fe6255eaf03be07d826c5c8fe03f2548f9e * md5sum 27eba94b19441541f44e743a9c289cfe You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4FiAAoJEIXCXpWhbrlNE4wH/A78sO6RCAw2ODsPTxmrzGrr 3Vj9DAJG0vffKS06hV3LlcFNWU1n2tqnH/le5uZPoH1bHoWcH3LH7+rqZHbbtxtx J0MkUw4gFwXOPYrMB1rtY7BfBjV1xqReBH5gNQYNyIHV0FZjz4aIva96XEIpj/NK FVSEtIx/HTkmL/JL11fvciRdDbjaM1EgOw7ZXPNndFC7lgXAUem6w4hErs66EId+ fqpbHmwxNo6dtVk3J7n7fZyspGSJy0JG5evF1JEQCU9m1l8WouRmjEJpicv/z64G QFBFS+v2B/MlT30WKhlzWABbWzPy8w3zlozSthItY675yW1QkcTvEdt9sgEZEoM= =31b1 -----END PGP SIGNATURE-----