This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-plone-12.1-squeeze-i386-vmdk.zip.sig gpg: Signature made Tue Jun 4 23:23:53 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 382ca4f7cd7b41b6d946660a15cc27822ff12496 * md5sum 90590e9486668f00c1be33549c03aacc You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrnb6AAoJEIXCXpWhbrlNX6gH/05XkA9oPEeObhzYiF9ZlGj5 Z1KbplzvFuTOOTygVyhYOiBPQ6Pa2DULcBDiLrlIu5PsHVmayjO5puh26JX8RUN5 VARAO9Tc/6KA1gpQVnurOy+vfwWljDjNaIO1b1cLcRQ5BhBJF/7mWDKj50BM5jQW MePsxeqsFtX6BzZPElxrn4wFnr69cywtOt+vX3aNSXYbhsgYrXVNEe9qBV2lmnHM knjBRYImwDBIlOycBSznW6l+ow8ls/BhzIbzPLmezGmiTI73m9da5CjXzjE8UFEY YKVbhDfYNiQO7gz9+zED1e7lqh0Hhn3NtRAe4IlkhOibDxnE1xe+9GzgRA0KwvY= =a9Pf -----END PGP SIGNATURE-----