This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ejabberd-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 13:14:01 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9e353e54cfdab3765b29c14261c35fb9d4d4362b * md5sum e74a65735011ee9205af77062a8ce5c8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRregQAAoJEIXCXpWhbrlNTUQIANZtvS2r7KYc5aPa3nttaZts fz/ISk/ABDtlzoSaqhWo4fd3GDcL0T1kTfFjC5H9c6cMIh/S8yA317tkozhC4RI+ mYWBzKUZkUZNMvGXNlsRb9sT21+RgAxp/lumkE7RBk4l+btlKVPyaV2cs22qzTOH 0/gfIT/gVOgJx5b5C3lFCOX78b6i2WyYOSohGE5Fox3kisxKBSPMyBHsp5ppK77D +UF2VEli+EEJXBYHWONSmWcAk/GQGk6ks8NYdk6H9+XeJfBtAeeRDs8rapY1VCnC ryiANzCVGOD/P6PPe2VKkBolnxvESa4jRY9mRUhBZ0dQC2Fz8ievQK4sk8LcviA= =Ehl1 -----END PGP SIGNATURE-----