This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:34:44 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum b8b885a9b30a06073c0950835f4e0b84f647a9aa * md5sum ea5b38755251ca256a28effea92743c9 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4BWAAoJEIXCXpWhbrlNKeQIAIUYkawr0u76ssQUGbL4+CAi OLfFGk2m9rLq7Ppt81zMHFLdm8iC2e4mEXGktC44uTlJ/QxVnA2utG4TWWreD4Fh nddsV2lKLFvX+Q2L7K500NfXh+ZPF8qs6PtRRkN42BrkoWVSRPpUGdk/DvZbzz5y qEI+67ZeK9C9wtsC16/yR+wijWpmV060zaMs3HzyQogLpPw7mSV74D0AOB4eq5VO IVUNR2yBCsMFwUUriYMqNn9hA/L3xhwcWir4GH1Bd274BfE6xQQ8/CYD6LIfDP9V IgIgN3jVlyfFIqZudRYw+38cPOvghwLk6dunqZP5T857tNLb7eHXCs0AXA5p+sE= =K4Kx -----END PGP SIGNATURE-----