This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lighttpd-php-fastcgi-13.0-wheezy-amd64-xen.tar.bz2.sig gpg: Signature made Fri Nov 1 09:06:01 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8e2253c14d33ff76e17a44d91aacd46a50ff6a04 * md5sum c1bc39a1a9d4511ba967c9d5196ce724 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSc27zAAoJEIXCXpWhbrlN2+kIAL3uE04IdAwHTYEXxOQxSXAc +AhF3/Nc3i/mxuFSqPVK7VDdlIlv2nB+0+xEy9/hmEX1cuaYww50I09QK9WQYH2z LorHnKtXW+Xn2hmTLJOtLEmXQssEUtG0ARgEZ8NHDicch7ZUt6zVphhVqjSianIs 9QNQuSdbzGUKfcfx979GDrOrLvgkXTkHIryQ+hA6iES7YNnq+80SQfI9erNNPRLN UXpTRY2KJBo+cGylBH/20yTu2GBhK+F6zjM/PPqfj2O8jYNk1KHZL3XPgmyKfT+E wRn1hHYzTpBfV6MfbIHF90AqSle0KULbS4+QVqtFZn8QdkjuicB8YZRxCc5tCuc= =USfI -----END PGP SIGNATURE-----