This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-oscommerce-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 12:08:25 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 0d0ddefa87674cc003f9bd4cdbcbb0abaa7ac646 * md5sum 8c8d45b548aa68f2a755df83e99a01dd You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM3otAAoJEIXCXpWhbrlNpM4H/iIg9T/TXP0xFnm7bi9xmwri mzAv6JRD3C8jkvRJqocN3pPsHR4m2J0LG5xtLSHAnpi8xqJPlXDr1ScTaqLNiQ4N wIImQMphb31MqTT8uO1agPfyGCTsV8DAgEHiuS1xknX0j6iPCCDxHPdjdCPNo6Ox f63yxdc/VuQVUP2WNTmXMHYRs3tFLuwiLReoJj4GzkYbrz9ATc5VGJF15lBLXp6f D26pF6QXihgSBXqUNZ9Oe8tRNS7vxIuDUaBJYdb9N60Ya4hgfa3u92hD1PzGpQxL O9ADHmzqE0hZaAtfT4Z+uaNbr6dpCSAZpf7znlKxbfBve0qAAZj9WJ9sG8pBZFQ= =gbbu -----END PGP SIGNATURE-----