This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-appengine-java_13.0-1_amd64.ova.sig gpg: Signature made Wed Oct 16 08:32:25 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 383bb5869b936224793fbcc49a00bbc319ef98ab * md5sum 24d7e260476b0ac03cd52c0934c34b2e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXk8LAAoJEIXCXpWhbrlNx8IIAK67IUuG3LVTvDfgyFb8YwMG o9eo81WSIyuF5nmYKi8B3VaCYwo0h/B5I/7cBd73fVRuCSSFGaEg+HEY4D8UtvWy iTmPOceoaFtn+n4XOdzMDXslBzc4152ggU1+fpuB4yVi8K0tvlcosm05GfoIFDNp 0PiwFNYuaAYgSS7AmlesdqXPOyfr8fB3x4Vj5BdA6XVHNgd5AUkgs7W8AYsKuFxC 0BpZejfj39lXA1J6PZGAnmXnAUgKDhVqW28ojDRAopmmbW7OpW9U10W4/crd77xt 02RpZXP3XT986Sn4QDpGwBRzuSzevjYzyt3gzLdHJu7pzVdrFWd5qfFOqurhQZg= =36I3 -----END PGP SIGNATURE-----