This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-zencart-13.0-wheezy-i386-ovf.zip.sig gpg: Signature made Tue Oct 15 20:27:04 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 883c0c2e80b10b7fbbbd33f6152f323674ad2a41 * md5sum a65b2ab3b7ec60c813037107ebf5e983 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXaUNAAoJEIXCXpWhbrlNSCgIAK4Xgectm+rvgZSzXYTNJuoH UMI1DfTt59v4Ooiq+9gmPoQ+A/R3tozKgi+2fejNoyAoHSy8++LfxDPxGtO30yRd 8+MARL0hbJW4m386JfE8WgVDp9k/mYcbZP+SjIv5XLU9mQ0xdJ3XuW/il9Y5J1eS P2H+WMMZ+mqypKjiBneSpR32sm1GjTisx4EthK6ULFuvTUuYAbDjmw5WEDkRBJeB vPiLvhpg231RTf8Ikseq2C+mr6R991BWetg2tfhUaK58e0Q7fOWk9gx+dwrYkzQ3 bhDFTc3ImBB7Aa2e9fd3DtqCCEQIYxDsuAHhWwSGjwWQYkbcS9HZMAvrYDQKNYk= =sF0/ -----END PGP SIGNATURE-----