This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-appengine-java-12.1-squeeze-amd64.iso.sig gpg: Signature made Wed May 1 12:12:37 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 79741e61b44e59bf03ee62e699091b1985b2fe57 * md5sum 9dc203dca4b3cc45e9a9fdfbd3db05f3 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRgQamAAoJEIXCXpWhbrlNAUAH/AvPq5YTGU2LO4lQaZAyAGeH xXmZBV2QeVnLBz8GGyoXBhaEAAiYyKi4a6f+DDdWKFLiNvb04godZuCAgoP268RU NNp+8FoyapEA5eBEjqEz6Ya3J3Ux3nmLx9hZtfaKToudePKHnpt1Ts3ZcfcQeEDE Ep3AscK9oTYw83epAJF535kRrIVKVtU4jxby5Tb1eN8NH1lC9Wi16jMeeq1gB0OB bfz3TnzkvfBESGVthP+Sf8vsWUb4Nlqw/C+z+JIJJTEek+WvbzKXHXNjX1Gijqkm +2yEkDyBQg+0h1h37xFATSJmt/MsjKEN1nuO7Y75FFRh/7c8bsL2ZYN3bwMqz/8= =ELev -----END PGP SIGNATURE-----