This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-cakephp-12.1-squeeze-amd64-vmdk.zip.sig gpg: Signature made Tue Jun 4 12:23:34 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum af7b20040d4fec8569a2b4197dfe3b1ef4e19a3a * md5sum 0072939d2eac93f80cf2f08892468df3 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrdw9AAoJEIXCXpWhbrlNkzIIAMkQSzaYOKpTIv1zaj3Dtwbh A15H/zzeAN6sNoIxI1P5wrM/zHbQ1Gw2oxfmRRds6Jtp/Ie6fmXY8vzh2QURlUzN XZ3iqDNBpxIkwV7Yuxf6aJZZK/6j616zsNYsoQtFTwsnn7OxsawrORYIfn954nu7 4aGhii0VEp6B5FoDEg4E5bna7usnqUx7wOGEWBF0oH9C+WBj+8IS6/dL8TWOVezT CamziFC4Fp1FHXf3qDCOD9ZRU1z4Vqyh1gc0jqwnNhGVFmICtOULW+4GdxmkTHIc WIeNLYFBK90tC+8cOHdaPh/2fnW+yvU7qgusNz2l/zs8DCoNVEnFuMiWxe92iZI= =xfOZ -----END PGP SIGNATURE-----