This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-apache-13.0rc3-wheezy-amd64.iso.sig gpg: Signature made Fri Sep 13 09:35:08 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum e508c712850e06dc784602ef4bd59f02656b0c8e * md5sum 2cece0f21e175f68af0304646d697127 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSMtxCAAoJEIXCXpWhbrlN1LIH/2dg13zvYzDujPdY7ziWryEU u2FAVh8qB9qiwg+VPZ52n5e/74R3gAUwZP5OVdJp/4cmddm936qWOAjXxyd3/PCT xEI2sRjjJlIzYm+7gPe+7aGaEt14Hov6bt+zBTKEQvHYlIiEtnpk5WzhN0975RAS +whWrQbpEGqmr+06iazGkklBTJCM4sklSoYPIpVnrvNPAAR3A9s8W3wEgZWSxLlE qSIqMPvNSF/gKBoy5YbORRaPu+Ei6ojWEsjUl8NV8cMRs7xOjtWUKHi62sOdhiKj O2gwmWYtBbSn60EqMFx2nv+m0p7cArKTRipEsgyvpqIUZ9RGPKfJwgiqSjfzjNc= =W6AW -----END PGP SIGNATURE-----