This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-trac-13.0rc2-wheezy-amd64.iso.sig gpg: Signature made Wed Aug 7 09:11:45 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9fbc3343b3f875c0219874ef3fb925af4b7c9351 * md5sum 8f6884da04837c61044b9acaea85fbf4 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSAg9JAAoJEIXCXpWhbrlNACEH/iSFOHCpyUpFyrr3Ewkfg8II D5gP6ZnMv6J2PX2E9tJQdtIj1i5tdsfbkeaR/wbMtsz/Fg/y3q2ze3fR0EB99ohw uCNRtGpcy4nbRb/HXiL5eF4kCwY8/awuW7oU3n+an9uYGcSVMfg0jWsHnjmH+UkZ UxWlBX4y0rZjJEOXRtU99OYQUEudcQwy/sNNMiAqEzWvbKjYEprE3HjplBrDF+FU fut71S7mJSVgaGBx0RaoA0mPOjAB20wEY/zOrl7WjM0+NnfhOHs1rLRpt0ufbh2u CM9yRRcDueM3IsAOQDMT5tKa/dvuxrCGUYtDUrb5DcnYQcZJgmF1dr6kc3jZbpg= =5TMN -----END PGP SIGNATURE-----