This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-zencart-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Wed Jun 5 01:25:50 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum b442524df8112d17ec909287114c8dc9b758cd19 * md5sum 1b9daedb1423ecbb4a2225e86c07a2b9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrpOQAAoJEIXCXpWhbrlNWQEH/A9W8NBqWFxacYhtKKEZ1nqd deVR9tjvLnYCjuoZdMOeSgbgKXPmM0xIbFGU/fBe8hvfc9Ul4JgJ7/XWGXkCwqrA A2cnfni0sknnJBjAU8lPrF05iVqARZqqm5K//aa0Vo8L6q7VCyDHu/f+oLDspjEB y/Ika/hM/e5KOqNb1saXc2bit3oknp0nq5+pBEHM5Zd+7eWAFt/zBVLPdvZXx+5/ CMxwRQtHiwBLCC/k4Cc/3T2f6b21G0FXngtBfFYD9+qhvlKZ6TNse/mnHLQM35u+ y18ZObCw/Wz6XOYs0FJO985O42cPvn3luYSV5bYzklFfHZVa+ve+HeZPCb4G+ow= =+PL6 -----END PGP SIGNATURE-----