This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-12.1-squeeze-amd64.iso.sig gpg: Signature made Wed May 1 14:01:15 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum df6f9191a6eb7fe5db868b18d0441738668b122f * md5sum e4b8800fd711aa5d66d685701e798634 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRgSAhAAoJEIXCXpWhbrlNhKQH/i6o5WtPVmJRgr58+g1hWtf5 k4x+t9IvXbqVIOw9mYmqzYdSAQ993DntZ0mGQa+qLRToKAUP/HpuiDJ45zWFuJrh mTTBMpQ6SyNh47KfsCwVCtpHEh5U37ytmI7ZIznXE+p3i7DE0H0KYpvn5bGCn2vn 8PunlwlxtDjvxWHAkh+2eP026TYk//7H10pSz5876TGrTv17b/jR6fYNprGGozPk A5rI/kjAv+06qyApa35ocrrGwAhp6TkTXX/dvBIHLf5jgPJu4xEQDWmbLB80qAmI w+ROfV2Kb3aKEwCsAKktLtmKwpBWEI1cwvPAT8PnHJcoYEZwbx67tFraNLXJlnE= =CVhd -----END PGP SIGNATURE-----