This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-redmine-13.0-wheezy-amd64-openstack.tar.gz.sig gpg: Signature made Wed Oct 16 10:24:56 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8b2a3f10faf2629c1fbf5c8716e066f10142ee43 * md5sum 7fadd72f06aed2e7ec919249fee0ed78 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXmlqAAoJEIXCXpWhbrlNfZUH/i7m25k+9KXahwym54aEOONT wKniHRMG99RN5Z+vmWElWYHFzNJdUHObw4E1RTStJDHCMKqfEc2vvVsqnX4rkbpp 8UdbBQpG997F8YJWI/Rcyji01JYVIXAX2UzYj23MMQ7VaqgscrcdTI22NUh6Bkme 6LC/B6vuxue3xOfFy+jmKCuwNj5VHSP2RK9yozNyZ2BNkClKt4gYNI/BOjSO0IQY P46Pun/s5TDVvtG95NCm63vgRun0VpI9qYUoXhu8ma+xwZXQPgNxOU4F48U3NjD6 cdWeG3+hyuEBlUkQouD9XLj2nYCy5mCLCkYx8Yd9DWzAC3/Oxgx9sk/1WNc5sn8= =OtbT -----END PGP SIGNATURE-----