This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-movabletype-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 22:24:53 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5c05ca4baf75c6916a0b2381e556c36cc69369f7 * md5sum 08a405974eccb3a596f263712c08c8e2 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrmknAAoJEIXCXpWhbrlNNigIAKn5dUs9ShCR8xEHSqfOZS7W v0s7Dz1NqVXaFzVvFtePDlcvomCAt6v9j35ygc/5REGaxhiIcbX6+LWnisJRQnWy 2wrQATtnIe3mqdZy6d+pxRJ/1BJxqdXGDERfLaI7r8PvvkGzU0HVLhbM8P+CwnKb Qy9445Kzxxjd/R9qnDbrq8PvfpseoPRg+E5UJ2810WXw1UO963rHsdn7Pj5NMfT/ 5epui2AOEjrCdZAivjd4R1Z0Q9/LswsSJViEdgR/Nphz4LzSVGF5vd3MscAXgeMI BfNWfU0orgtz9koKZXGpNLl3RBckJiJmngAKSQZEq3cxJxoNX/1oVX0Dh0LxIMQ= =I/px -----END PGP SIGNATURE-----