This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 16:39:25 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum c79fb2cd7a734456680d6eebe98657b5139e840d * md5sum 5848aa466e31505723758f6c564eba16 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM7mvAAoJEIXCXpWhbrlNNCAIAIVGMRdO8XSJegVN85lgMM6e hvUaNgwi7ibF3gSvKvXZcRYIYYn6oCX1TEdTn53f85UZFnk5Gk+u3L1D8PNgKoo0 NH0PDN1mFm1t7enItECGsDhpWe2E7EwAbS8t128uy9MCW4jfdqHKj1KCOWtbRjDA Oq0v2ifP6cXisItF8DSPUeCfNPmft6QFBS1u3pjZyFC9lxRy1vha33ZYiBNJ7X3M +KNu9aBNmPCVQ4HkWp5SgNV/zI9oBVq9DSe6i+8SsRcs0EpIRMCFbRyxd0taV9I/ zNZuy5quKNedrcEg3Oc9mrL1zLXqx4qQk1ggz0ldSUTHZamtUYnit2T1CRsP6n0= =52Ok -----END PGP SIGNATURE-----