This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-nodejs-12.0-squeeze-x86-xen.tar.bz2.sig gpg: Signature made Tue Aug 21 16:06:49 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 81dd4ea3a017ca1941d0656897d6665be7fe18f9 * md5sum 845b66e6a12af8f46e179f672a50a111 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM7IQAAoJEIXCXpWhbrlNDiIIALDg24oVqcGYqZAqICSO0J7G N4VqaXiRX5oQZcsNncW3v8ARCJBlP+dhF8LOjNRUkdeaSzV2P3fYBL/jTd88KTUt 3nSZETejo7p5cdMwLYqLbBOlbYj2Xt85TaQLo2YxysSgj812bmbnNzCNVYJhGoQy ONrubuhnJvZL6q8M7lhFJde1ujuDKeznDFYxwNMTz4RUKRlVGXUluJ3bwbqlGki2 7bh4zdv4Zmnvorbk1TVU2Q4SqRnS5kRfxk9ExYUrD3jpJS7nCn+e6MSTigD9Gyq1 lvQyHJqVAm0vyhX9ISU8OcStkzN/Nq8xOpP12LMVByH2Bpj9q3QymcM+3fZ6U4E= =mFV/ -----END PGP SIGNATURE-----