This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-7-turnkey-tomcat-apache_13.0-1_i386.ova.sig gpg: Signature made Tue Oct 15 19:37:05 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 65d48f25806d47b9e2d17c6b25e080c1b471adc9 * md5sum a5a933ace9180cef832a17cf0e119e7f You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZlXAAoJEIXCXpWhbrlNHBcIAI1yhmFZXSscYFmBBtVevcOK 7L5EM0HFeDeRX3owijd/+zv81b1gW02eY8AhLuU7IOCAJXfulVyQyPSLE8VjkoAD GHCjztms+YDBT9VuMlju7KSAPB2/JBcLYFLPrY/H1p5iBSAwk13plN3j0QtEKZkN uyVtjEowC0Mrwy4rCVGK3ce00c888c6y8/InynqP3g8WAksIbdFLnlHoXXUtMoRT gu36rgOLc71/yoOceN8/sE4C+/VQXlnSyg35mJS8ESm/y8+O1zUipP3eERROjgwF vuubQ3GdJezPgoG7v/9RtSt7qWVvd6YbKJkcVswl09JbekhaRkkz/QPbwYtxmyg= =DKNc -----END PGP SIGNATURE-----