This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-apache-13.0-wheezy-amd64-ovf.zip.sig gpg: Signature made Wed Oct 16 10:26:14 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum f9d46f1ab79456553c27b1e4615fa3ef3b4f0cfb * md5sum a202b906faa2fd644fa41190f70b87d7 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXmm6AAoJEIXCXpWhbrlNeGoH/0rp40QBn1NgH7C0d1YQWHzQ Zfm0KV5xo7q5SP7sObw2Z124GKc3CQOUrVDdIW88vs3eoC5iUwMJgQ8DWhWCmM0N S7hE+NkDHNae/bpnq83Nh4doW8zRFG30RAVCnIPqOrtqfFs0qYY/uab2WmXgyRZQ Ecd4bwIluVkkcDGWAhciHGhr4MrueCozIo+mLl1SrAzwjIgBJlENc9U9VHGQQc4D AydmA50oxnyRajTir0gzTRvdNLY62qHwtYzN42kb7iTCkYilGdtdCqc1UJOj2IJ2 LO0ZHJtjkBs9w0g+SeQC9m9XUt5sgiHFSD9jQlevHcsVRqqgky/7SVVT1DmQfL4= =EssB -----END PGP SIGNATURE-----