This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 20:36:19 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 17d2f45df88f8f040c516699723cfe85c4513cb4 * md5sum 9eff46f39bce0e7fc3e68e69b1086536 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrk+5AAoJEIXCXpWhbrlNI8UH/1ytw4mCiDxddURvGqoJNUqN rcWrxYKhWmaQZrw8S4g14BGOrqFd+Vi+xu8mipu8GH7fA+ZNwYIYr/ikDYQ3OSko ywOdqNd3beNe3S7Tbp7yXjy0BU5hrUlgL/JgT2Daf2t4vVJVQCSTUSQg8haLKOU+ Kj9UJR7OLuC/RXv8FSvmZj2TtVrU6B+L4gKtpBITO8KdnJMmPC/hyZGKov9NuVWZ ODJ9G3dCqQ+yoU7Dubei24OdNBVoRfmjcPWU32bUIYjwZzU1c+RDZCia90VqyNxx KM3CU/nNNU8xJ+YbeS/5vOvHXR0xNXWh6iLkYeCRQankWY4OAlVL17TpfcUb9/w= =j8LW -----END PGP SIGNATURE-----