This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-python-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 14:54:09 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 555b2996321e3283648dccaa42ce5fb03c27e79a * md5sum 108e6636bd7bbd4be02f5478d6b7cf4e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXVcHAAoJEIXCXpWhbrlNuRcIAMjt36n/eA3uLgcfy45SyZyR sEm/JpE3HEtoRupNSsq8wrsZupkZZ5ts2gTMa3Pv0wtXPGrCJSXag46WbT3PIPTB hHm4Hn5Wts3KIwSarJJYFFEQWoxSAcqYCLd0HuZncYM7ExajFRi9dYLHrHlXj4yQ ziUxuqO95Bh5A2d/EAc5VemEkum38h63yW1/5PVLuS/bUg6u+ruwC8+h6h+sk7Z+ 66TinKOeFZO3AvvMyHtJgQqMMuWQ4PRTZktvMes+lzBlyQLLlS/FGLn/vDlip/Ax dWR+jGpOBiCnRh3C/woE9PmDPa/BrPJPhxqqNhQvMbxiJCN4VEr32EfkmdyWVzI= =rfXH -----END PGP SIGNATURE-----