This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-asp-net-apache-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:11:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 752b43f1681714c0817f089b4415ed4c85adac90 * md5sum 97e31d92c43c73e9bc2c1e99c2a66fe1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXko4AAoJEIXCXpWhbrlNWLYH/j/QcHHmkCDpq831ceS59PKu VrvwqVEnX6JBAO6onTezOk1QBDu5JvCwmDTEH0LnD7IBAyUD9QE3zDv4ZijGdfPD AR6NRMMfON+OD8i3Lvq9emomJPWHVLiap1SVNRMI4uZ/AA6SzHdcjmOwtEcr9Dos 1Ch9SLHMyFfoGvtr7Y6BZdeBDz36PqvsflUCdW7nUTg5DvMy6I9bsJ1SCipOq4zB cywdVaAxX5f781UKvyZ5bu2zDWeXjQoX42yPOIjhj7LX2QzNPGX7KqkBqWSy0K8f xlTQhFxK4V53H6A1Gso3ML72eZkmQDvi0tyFD8dKDbf4ApgRGhS8HPq3GfmHPns= =d+I/ -----END PGP SIGNATURE-----