This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-java-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 12:28:32 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 004fbac5a12e8f83006317838ac9e53986f1a449 * md5sum 2fcb028f700eb10249d7169200ffa2a1 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrd1gAAoJEIXCXpWhbrlNfDwIAI14GZ7xDs4du0Xnf2ibc6Wg bkIbweChjwOcMGnLt8HJpJ9CNg477pJVSwXzm196Phm8lrhqYW6bwbomQx/vrj1z +08ABPqvrh56Fiu61H971vMJBwyPNMWuO2O5cuBM9OWw3g8hH5bmjiUCP+1C9PB/ sMmZGGOxVJxeOFq6kqfCW4SW2E/eS9AjwZMLDO/vcEdNbcZYrnOf86L8IgqO6FEG gMgiLUhvaz113wsw4+P4u3MJ8aVKpUcnxrcrwUW32t3SlUwJ79Ojm9lYf6sRj7pV hPV4SSBLrwaBNo10kewhs1ZR12IdA68h5QF1YnZxkrqz8+j5u9fKO6ioyLfqwnc= =qufJ -----END PGP SIGNATURE-----