This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-yiiframework-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 12:43:28 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 6ddd58ef7c64c2f06d2bc15fb327e8e179b2642b * md5sum c1f40000d3741d953e00ccbff5aabbeb You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4JlAAoJEIXCXpWhbrlNq2sIAKkFjwMkCTliAje0CTPcXxcc mBISb1fhfXtYbFuT8Xx8HuQONFydmshrdlG8GohMgaeDbfym89ZZQJGtqPS/8IDb YVfl684Nn0HsV6dPSZlQBE5HhS5iZ8j9mpQ0+cn7HREGpNtDOLraX5PiOSirzqRe jjfH0uOdFwRFmPkCOn0N6rZ0F/+hJWPQlz0WxARZrfi5EiY8ZWT+rCTb0xuVhlv6 XZKXZBPSQClbrsghgheXOjD7ad27PvlF4gPx0SlOt57KaJo8rKzviQNnDJFkWYBd 6K+Euy6hApyeZS4lSZobHg7qjtPYFy+K3P5r4MWn9yvNkbtHl59nV0JlluaRGms= =1vLx -----END PGP SIGNATURE-----