This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-bambooinvoice-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:16:17 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 677e892a283df67e70321c80ee34e5b4ac8f4625 * md5sum c64c4bd84eec470aaabcc76633a19969 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXktIAAoJEIXCXpWhbrlNA/gIAL+IzVTXLaVH3fn+HoMJYs28 8k24hSNP30DX3qVX3mbzIzTXpBVf66QyQ7S4HHzO/HjgdVbZclZPmNAxPNWBt/PV 0oVVF3ZIpY/vAw3iJ0jiRoU2BLgCvHdUZu5CCOWZLQmLELpjdlg1NeXsJVOAaPym 1ZYjSsD0IkXXIoRYX96bZQrNY6yI751eywz+pSvOvZuAeZvi+vLVDSb68nhCMmcf Jd9cr4DT0Ug81pqqJ+jg7zQbKlQm6AYylEyKPAamX16QwgHZgV8sVx8yJeSH1WmW uQQ37an7mHmPzvGjOYhCQh6Buylp0rKXGq8u/uC3xfS0nUMBECE/0tTC7ddu5V8= =0LQ8 -----END PGP SIGNATURE-----