This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-phreedom-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 15:36:55 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e91602894d897c1497af05ed69b42f03dcbdeba2 * md5sum aee7c6e46b435f539a5c8d694bf9d8a5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrgmQAAoJEIXCXpWhbrlNNRYIANxlZe/T9FTwJGu/Xej1Hvux hn4ROKfC3lTcADGcKnuTMYGe4cEE8L1qBOfmHoTHv5erNHQcDjhia56hA7oqx4rQ JRIntIwus4ttMEyiiQ1yqxd8m/znEbLY9Uy5vGpFDcelTHGFNKCbQo0zYM4F4s0h bEVcdgE+iQX3UKR3EB0eT4X22tOKYEEH0lQaursoc497ltMjV5IRuUnVMRl8MYLP ML0H8M/xVEm4tNnTfbgkpAOwQWL3bkF/Z9cEVJq0bl1nymqvErpV0+suzcCwWZOe v1szP+aHQft7k5CqSpGBnir/q1sq7mEJWQX60+jEiRmqZmRlYqu1HMBUeZ+r5cQ= =jAtH -----END PGP SIGNATURE-----