This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-plone-12.1-squeeze-i386-ovf.zip.sig gpg: Signature made Tue Jun 4 23:24:09 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 1c627c76d1f2552e52f1b93e3aa8c9cf6474b3b1 * md5sum 541dad7d8c4eddc7b0003e7741467c71 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrncJAAoJEIXCXpWhbrlNch8H/RZO6EQ5WVRm8McX8+PSx/dv kYE6knxYI2zSKmy08hzLCGUQZAisKE1Gv5ahWQljMXVJLQMXciZqJu09hWlAelh/ nsaer0wWNXuIJ0s4F6iG1ZqH3UYHymeT0jL4LOcbG9hWOLQgC6UH9c9JKaZVBJQp jo+cbaMKDSN7DXHkxQTm6tXuI6JGQF4/k5vYBoTN4x+zHdLcOKor3oNbf8ev127v Wv4HqHeDdxKUwhzIf3GCspX7ZBUZhNClDeC5jfTjYNzsk8usGnspX+j0ZBK+WL6V s5gv5m3ioo6ssUCplYx0Ib6Jl247DO9UhzCLo4ih9bFiNZVSY+n9qdO951TOMUs= =CGHo -----END PGP SIGNATURE-----