This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-java-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 08:52:46 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 2683bb89435af7a14a0b63c4ee4f07c4ee9f09d2 * md5sum 77d61f4792c623a37a4ca34022165287 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc2vRAAoJEIXCXpWhbrlNkGEIAKY5B/8m17tGxVIVpIqjaYmI waT/uLOXoR66+agb+OmrI6VolxC2mZelimtedYvTSWatd8yT/rltgqPr15X109Af xnX2fpENq8CyYFCtzEjQHOdWxvi6SyIdt8m5LapIq48txSKRG0NnYW8LTMQa+hrP fQGpexvbSWkYUtli2opH9D8r1sxNTf4PQEnlkeYkwPY6xaymw/yuJlPIffZ5UpxT fdPrO3d8KW7DO73wfaKh3gCPrVabX66+HZxEXp4YpksCxeV5bMnDBQKJK8DsdnFd aN/LdcBbUCtDDIVM5gYKehYaxfo20UQMCpiLhHPVDJf1DyMq3gGqHhIbUN0EXc8= =EFvo -----END PGP SIGNATURE-----