This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-web2py-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:41:09 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum f07e9d28f667d09daeb7c83e845428f25b3aab71 * md5sum 0d9bbfa6588e672df85514bcb2b8e898 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4HZAAoJEIXCXpWhbrlN4b8IAMpOeTEx75WntHJBpSHqZ+Eh CkPTgFKo/05PvztWNffEQRzTnsrnD6CXyZlK9soe2pD+Lzel+bkcQH5zXesql4bg /wVyiI/dTEMOno6buZ+FbRrn6sZrWhIn6AQnMID26xN6EXRSD8DNEmVaASNgM/z/ 0NLbeDlN+S3czjxVAkQ2Zi7CNWDhN82aA40V3xK32/cbvumSjTWQGRe+WB0GLepG SF6NQOBCF+Z8pU1b8LwQ3rE1Z5SKmEAPYuuew3X5F1Wvw/BIkYd63r0XZd3S7hW1 EwYAWk6gU7fKsgrFkLPXzTi/wgjpdCjpgFfL9LI8ooOL2MhYimFzu/pPnXacr6M= =n0Vf -----END PGP SIGNATURE-----