This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-b2evolution-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 08:45:52 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum fac6662133f24a6125551c63ef914f905d3321dd * md5sum 477b492b289aee841def3968b3642f35 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc2o6AAoJEIXCXpWhbrlNgncH/jDiCIwtnZkofTAcgWyLgH43 Qa5SWq8C8Y8v9I0CCI8q/0QCRP6eyuSuR5YPMdvlBP7zvJ4u/1Wya+TFds5S34tB /RclC+DhuClaRM3++XNlgMVcF4kK5M/GC51dcwDbrVsp8E3h8bocrvAaeEFEyHzO 6m7ezVziCbZGJFDrOlgyYmwwYyo16s91vnHeXZYqP6QXkHwbO2jZWMfntQBpgyCB Xy29VgBO60h/yMgxFqhNsbZhhP9YmP0kqERNT5B5bu3GLiZXcwq5aeZcPCn7dkBe f5khdpfXUJO+6k86cdg8s6OVsV17oulZPUvgNFNxuIxshq3J7b/EWYgKWvZoi1M= =jtQy -----END PGP SIGNATURE-----