This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-core-13.0rc3-wheezy-amd64-vmdk.zip.sig gpg: Signature made Mon Sep 30 14:26:13 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 6a7a08fe30ac2a0788a47f3bae2d4f5a7b3ebee3 * md5sum a0c5d4f0337e7dba0e9800a4572fadb9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSSYn+AAoJEIXCXpWhbrlNlq4H/0vW26twdA5fgOapDwX02SIO b7XIYK8KIhRSnNGEzP5kJQ/UJXnx3T6o6S65e2TB1IXMvRWUSdfdcxVFXXpmc49p 95XYs1BORR9P08IqX1i6Gc0YJLwHRsioKUX209zMkdJvXFWzfdwG31AlujueRIhS XvWAX189H6uZHLHCoaxC9ypG/gTr8nIN3/k0AmVBXiC+0hCYQ6++uHL0qqjaSyn4 iYFxniEEL++i0zOpeVr5ybWKwyvrsXCNhKH5QdZqeXXNNUMXq4go5myBQ4UQt8BK N1KU20jUVk0FGvGKGv5eUkZXSy4ZEonuE/WInQbtgLVG3WbG/BPwnCZFptsIBiE= =djKo -----END PGP SIGNATURE-----