This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lamp-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 16:15:03 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5a7b6c169403300ecdc35289a4fa421b90f7e287 * md5sum b07b51c504e61e5d91aae381ffd1550c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXWn8AAoJEIXCXpWhbrlNAjsH/0sEEiyYy36efj/ZLHfaTk7C HgLxporMVXLXg6udN/I4UfhUs+S62/UoJwwyxFjZ8rluYL3fhlV7IpiOa3ivQ6Pv 0IpKVjtizTnsPy1tAngdbIX9LEPqMKT52M/+ZLDJ1xnee8RiuaR2kwXiLtGL1b3A 1H1qAUesl2BNBtPwGR/3ayg6ZqXC0cx+obYDZo36M+nBnzUObe6VST8ccIHpmyY8 X3WDAKgSL1JPRtI+2PwYMf3GknV2KBPQimvA1WX9JWLt9hZ0NjfmwPqwPdFZtHro aMGxuAxGp3ykIcEX4jcI5tafdwW8LBM9IPAFSDGwh65IPJmi0inZapa1cUn7cPs= =9+kD -----END PGP SIGNATURE-----