This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 22:16:41 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum c0d98cc80f28aa3e65ffdfd35dab696a34071102 * md5sum ed90374d02f4e76a7b4330cacc0eb3c5 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmdBAAoJEIXCXpWhbrlNAZQH/RTK2jh8SgzNtKD4LAVcBQgi gSmaSlosYszMZ+mrvsr4P1EnTcrIamMLAOpzT2PVjR3Z6luLWU5wPuo8F0MPCAcU f5l2tHihO8cMgjJabcA76vP4QxHfBQ1S9dwJd7vKpxinVAg4GMcfxaxaN/q68dpp 8aKsrsw8sDC5KtZCwVlEiw+3K8AMo9c6P4ocF8g1AvbTuEGyBJoElblvNtbbn386 iGf5htralwZJGZDLZw9mx2kVgup7SUvAKBwUhA6XgYFZ9zcibgkWH4n2ifnG9ogY aOE3gWIzr3le0ilb6q1qfrX5lrwxcvd7We3U0YXrMPPCmrH87DkMItk/rqBxOmU= =ZzND -----END PGP SIGNATURE-----