This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-b2evolution-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 08:12:40 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 25d9fd4078d8a6d95e38e25f865473f2f4a013e8 * md5sum 1c062b08d7ef4c42f3625d00364c0ee4 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkpuAAoJEIXCXpWhbrlN1t8IAMqEaRHKu3ms9UigDgjuZEGw ncm/5Db9lcuE/UTG06/yKMWLK33p++Ib5RjLhs9vvIJ0RUUWuYzoXVEKkFABbZn9 CcJ3oBin+X7EpkK2f3nuVc1Z86CuML/koEWiU0cbSdQ9jcy7/M7Wt70OBnSLgszm BcR9X0qezInSChVcUH3GYd6vA+tEVInPTF3VQ+5dmbJfYmbmU9eITY2R3WvYl8sG 5g26HFHV1MBbuig5nTxZdrkLv0+F9pGfVyHNziS7hPtiVw8ihHJV0be9SO2wYVIg ZITOBYECg5ssZDLRxs681nEKcL3cknq+MRC+5w7YrFLWGoH/pnmkxCSLaEq0TeI= =7Zdv -----END PGP SIGNATURE-----