This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-vanilla-12.0-squeeze-x86-vmdk.zip.sig gpg: Signature made Tue Aug 21 12:37:52 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 2cd71fe8c228e5e84317cc29fbc5bda4e6a6f67a * md5sum 5824dbbcd723815a4533155bcdf3b782 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4EVAAoJEIXCXpWhbrlN3DoIAONXrrNjfiZcxOoRoa6mbypj SgX2AwySpST80j+lDPOZYwkY+UioLF+Doky/DwCl9lqnC8eyHtc4jKRsMl+67qUC YCSO5wrG+ygTT/UcCs1dUOaCnJM5YJvHVRfDKbfiTGjjEohPXUIqT5RAQKsPG9LO UyzTnMBAcI8eBqkbF4Mi3RQ1jWZAOK9ia5CnbzTxplu0z3Z+RMHWdqZ8zikI+U9G pq0RYqB7M0KqxQj+DzUhjLnoSsxgpaU/xsmAFCuOycJWnHWKytOZ1MYscfLjUyV3 evcOYqXpt3rDA03gqdySyAeV+93A9mTR/dSzq5UpHuYWcvI/5n8F6WvzElIN8Do= =6I6C -----END PGP SIGNATURE-----