This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-13.0-wheezy-i386-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 09:45:02 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum d739c6352e0ab8dc9c43800cb43d1b27ff471e1a * md5sum c5d9ae97563fd00fc71c628a368ab816 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc3gTAAoJEIXCXpWhbrlNSywIAN9p7wMVcC0FIb6mZgTkUDfM IXowWvJI/TPCOdw+I/ZsemD4njsZkGi1wb5k9cf+FbDAxwow5lNBJMZp/ov7nENr TRldm8r22pAvJpb0UIqFn/8H6CoSoSspNhQg7LgN6al5Bcv7j992krl9KUpYjgHY NHCqW3q3nDxdIE/0mxthGVdO8CpolqaXxQGu6aEtQJg5qD8MBo6UoJ/bn3xbzhTt jLECRloawPG6qsqgswGYUyTz76yw4gvEic1NqZXz5O9BmvpRPRAwTcQqz7cZzS6F tTTRxcGqiIvL/yR1/zY1De1sOsmWmKJkWwTAn0Gmi5Ahj6gqr8oiMbV/vKv/q+M= =WaRv -----END PGP SIGNATURE-----