This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-moinmoin-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 09:13:25 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f945e0b17bd2ec57685fcc0e556e4ebd66901822 * md5sum 6322357736958a4cf70a6b70f7eee38c You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXlirAAoJEIXCXpWhbrlNy9gIAL8S1EjQ75xrhFb9txpp4Tt8 MSbuJ7Ni1PZZe6FhTdawf5NiN9sa9uvRPuTzyINAuBEAPddNl6gSNmzP+8wgKg0a Lc7MkxUMnGz9pTRl0FoKMDlIiUw3zdupbU0C8aRUnPGL40yDlxqRfoy5bYsoO87Z ccL875fVmFvpnBxQZQ9Nxg+bVFU4Eg/PZjz84GyHroYbz4KJHeQ8e2W3GKEVTboc ViyqkejmQFmoBso2g9yoQkyIMxzKqJsxUG9E1FmsSzAWpCDtxXcn9QRGOFlZPWZQ ODbTn1k9kgjmV5+fxTM1Vx2b9X9g0N4Nm8YET59xoYNrDrPy+Dm+we8aqnPSZcY= =qakM -----END PGP SIGNATURE-----