This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-ejabberd-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 08:37:11 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 1176a542d4e96951046e496a07de0219788fa3bf * md5sum 12f9859de075a0c220af04461caf05f6 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlAuAAoJEIXCXpWhbrlNsiIIAN8fzRjCH/BYhc8BHgvHjn8j oj+BRlxlErjUFpETZmER6U6cOoTve3Z5eiYQ3e3598YY2PglhWR5eUG4IOJIaoFn z0Hw31S75EG0VUgvbO/DAjWdifk5JWVYBDsaayHoO2367JBXAQwQvbi5tLfBOhf1 iSvcWggw19kxjHVHL8xgu0Wj0MjxqUg+VGBOfrVyGF8kFdCetZ4VS46u851c2em6 +3pIz2bwgBjNEOAQD4itJnsLEugAXq2ope9FzvbivAhgo51cKS7gfcdbKo/eOkQy Y1XR0VZideSt/ARTtEWy+X0J0VLxHU2TsgvIFNX/v0guO9S9QxZVfGVy1Gylyx0= =gLz1 -----END PGP SIGNATURE-----