This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-canvas-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Wed Jun 5 08:18:44 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e38a4846ebd8cd3ba984390b12b8294bfe7a299b * md5sum 5eb186d33f3d38c60e6e736cb673e0dd You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrvRLAAoJEIXCXpWhbrlNYMkH/3u8uKkN4eqLKPD1BQ3cPv57 JP/2r8SnZBetttjVr7jsR4iqPOX9fWT8sHmFtzHN7EFI/+9I5LehTjTx8kjdoJ9D 0jwaxh0bTMi8ljH8aJMZBSd0hLTOCzrhOnsQCq4CYyTrGVJQNWdqcWFzZ5Akodl+ krThQ8IMlJeuiCagIaCcJl0PbQl2TF9GlSSlan8N9IzmtLoCyOBBzly0CsdUz0HL gBWlhJgvtIuN8zaeDO1KpprV1yL94uocC8CHYE4a/hoMCSycHckmOHhqruUdTXBl Ka8sVsuirowGq7pbNhWSLeBFmkczR+3pvu6XBjkyDrt6RHvnapgBiWPZcvIY1H0= =/GzY -----END PGP SIGNATURE-----