This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lamp-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 21:35:16 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 52e20d8110a7a1ff166242832b6c397807fb3461 * md5sum fa41338941c31afdb06c16355be344b8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrl2GAAoJEIXCXpWhbrlNFJkIAI29cGN3KbVwNYBz4f0Oyi5r 5J1gLxJYukQPVSDkGrAmcGu5coLKcuC+wZkiZh9F74Nrr5gc9+Zbofw6x0Ffs8y/ 9S6zVa2VYGsOwFn6QfkT1x3peeUAm2TvoZMZbs3weYresMwlmR0o3vyL/5X9Pt7J 60ToIgMQIfTvlKbgt8FNpImdYwh15K9hGETXhfrakiGaJ4sSI0RGk+DSiSUoTR2e ZMd2Qzkt5aku/bvzLKugGhV3SWS2UsLj2Acs/GFSFc1Cp2ezKX8ygKwnwNfOrnoE mTVjns/2xZ6WgWE9exEPrdcTT5250rXCronKy0e9tpQz8DgOZ3O659yAA2NJYuI= =kvIg -----END PGP SIGNATURE-----