This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-movabletype-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 17:01:24 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 5afc8c53abc37d57899b83b6dd82813d80a8008c * md5sum 4c10e560fc5c02875f9be32958783d5b You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXTZAAoJEIXCXpWhbrlNElkH/iOe3OO2dQB8BqmGAhuplmrx S6YnmBUyaOwAG/Lf0tSwvpBOj7J43456rpHVPD/GY3d+jpgR9uFTb1NJKHua5D4V PamZ6uJFx1VVOz9oXi2//5+Dm81Dg4LmOiiFpBSXXNk5DGCLRZZrxCaIl85abtlo jruCdO0ybS+UlpxKmDqD5qOzuyTQR73ZwY30Z/ZDxCdbIGFvMq6/1WbJNOB2+O1a 7bdVg8UR1CDwOAeClllSNL9tSx0n4BpiO6579pswXhrymyjpMAU3ic4NqlMZApzS a3BTacl86Mkav9x1/L5N2VTAPm5YCAqg/QimTLjfjj+G0D8yv/+iQbZXw10ZNMg= =xT37 -----END PGP SIGNATURE-----