This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-asp-net-apache-13.0-wheezy-i386-openstack.tar.gz.sig gpg: Signature made Tue Oct 15 15:04:54 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum be9276a1d616e84058fc3470d73582a61e2f4aba * md5sum 849dbd203aabbf2da6de1c12d899e65e You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXVmNAAoJEIXCXpWhbrlNEh4H/R6up28Vp9ZXhlkIl/TpoiIl kC25zOa6UKV1d2YI/NpEvGBFQBj5mVJe8lcQ1rFGkufVVzY8GrFKcdvikonuukKl gIyXxd65UJbTHIoV3r5ILmRVgARUwJBTcR817zn3luSAVYFpYEkgKePvMS5gZLJj N0owa2/+do11D5Q/5mV3Zs/A/EiIi67HKv2mi4QxwCLO0r9vR7E7ao1wjmh/Rwug e3kL9QlOA3KBaSf+dPOWZdvjatOmlUeFrmDRN4r3UnQzHl6Fz1Azdj9ymvJ4MgeA x3HG2bxYbF1SSaPadGmSehi+xv/ABGHuV8whUOyW9W/n2GHmTgh6AV+d22gUW5A= =HUhy -----END PGP SIGNATURE-----