This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bugzilla-12.0-squeeze-x86.iso.sig gpg: Signature made Sat Aug 18 16:54:18 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 78f45fb42f63462492f0c8f35273615c7664ce6a * md5sum 40ebf0e57d8bbe2f7d07ac762c77a88d You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQL8iwAAoJEIXCXpWhbrlNpMgH/2xptHCgsND9+QOMceVKM/Xu A6x0oQqhuzE0E7ZL+a2RaxJhj6mGzGxUY+kPU7WT8+V6+lXw3h7U+fWx4Yt23dVk +/6WrB6G6Y5TUUaiXe6WDZTVUeM4V8wZrVly4PvZ7oS57jD1Uv1kigkwMlkCznxP fDi5+/xaNLSgeFBZPFYA9Vlwx2UON60lJjPGLPQn40BhhR9jqo66LVqVHc32Fa3X b7ozIRoBWA4bSqzoA91VCWspSRh60SZN46RJY9nMiWQ4M7baKobz3mWbYou88EnJ uLtNj5vdj0BqK974mWDlRufcQ8TEECTTIg3slkRP1gfhevDgv6qbVQKezuPXr4k= =t1IF -----END PGP SIGNATURE-----