This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-silverstripe-12.1-squeeze-amd64-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 16:09:56 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 4527cd1160bf828d8753dbb19fa814b3224668b1 * md5sum 5795efbb635460182c6a8e49f7427478 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrhFLAAoJEIXCXpWhbrlNNdYH/A99eqairCVOJthjwllD98yc ggcIRo2uRH3mdqYDbA0uLKQXJz0ghS18l95NWPp3tpp9loyXi40ktKWmRSwBcS0I vRAstlljrQiyrNk+UycJ0zKFGEDAjmWWV6bGVPXah7ovekuUGGtcxNjfofq/mRbf ZeSSULw/1TylumPa3ZuXFh+n4WtS1qsNir1g+fQF0z28FwU4qvivIzHkPq0Blnl4 e88pyFxXrpg/iE0nCkBe5uShMfOezrZObjeizWYVODP9Sp5rdsAVeSH8Qm2jps9A +w7o02BUkpoOMuTmN/W+zd1M/enr9Q0kS2AYJ8lvpFGzyG/JYzHvkTo/5lo1imc= =/NY9 -----END PGP SIGNATURE-----