This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-joomla25-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 13:55:42 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum dcd37afd518fa9a68589f9ba9f8a1662d7965c89 * md5sum c21d22d319779bcde332016f6d2644bb You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrfHXAAoJEIXCXpWhbrlN/cUIAKnwmruoz+hQ3l2VM9UQLiWM 5Lh934yL1B/JE3mC/fqgxZth63w8MBSt7E/WuiQNn4NH3oXii/zrzsiwO1f7LiIR Xol34imC2PRrDClanrkrenNCpdFpIhXH7vOUluVG08znqK1EKnAnplfkd5AHFpH4 AcqRJv4C8c7NLNeZcyojuI/Qo7FkI13ShYaS8IYUcCqxmoK5vkqm8kD+/LMMV64U JWCh6bYZVkSyaX2RSnWzIN69bj6qlRkuDUeq/92AsEriT7YGxZCBnZMDImjUQoIg GsQkteuqAIOOHusoHLNSwzb9XEG7B2hSOJDboZLGGEjS/cUfh+nQqC6jomHO0fE= =QpHP -----END PGP SIGNATURE-----