This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-6-turnkey-concrete5_12.1-1_i386.tar.gz.sig gpg: Signature made Tue Jun 4 20:22:39 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum ad1887190a47f8e5be9f03f0b4ffbfbc0c1bd7e6 * md5sum d52848cb7b4cb8683f70927415c3a052 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrkyGAAoJEIXCXpWhbrlNw8UIAKbtj4HtSG09GKyRxCoBu73p jhxTB67XQ3+QgzBR+JlLZqFMejUhdu3OmlU0fDg4hrYvcdPO2UzKq9ZdimFVXbsm OmmYlPqv/ucHE5pD4NFMVfIzYtRcwZWsTUQ5Bk+gJvUbgrtQB1txFWszjUDsSvJP 6ddetl19fuSd72t57QcMgoiQUXF7S84PK3f1zpq5ZYetHCXtmRo0WiPMOeUwTl3T AtmR46Ow0Xfb9rmac2JJYPyrgR5cgAXisLxfa3fLBPbUwCe8QYB7cTpuet7jKN2i eoiG557ZeLYIs6wGLVgc9o0AgjU6Xu0KcyjPZx6dc7p+biHG0QFCDfk5yOxSSzM= =d5cS -----END PGP SIGNATURE-----