This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal6-12.0-squeeze-x86-ovf.zip.sig gpg: Signature made Tue Aug 21 13:14:42 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 02bb038494c4c6f7fab275fca2405647e86a45ea * md5sum 2ecac1bbb314450b8320c6ced3580794 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM4m1AAoJEIXCXpWhbrlNjLoIANItkKUKoJEGy5inyR0B184A XdIdOcKUECl01IMdOFzOCH75unYkrqmEoduAUpJoPvcQEQUcICczhQSi+SUU2AX7 tAN/cSMQ1xPJ9XzQIlg/Vgw8Xl6TC0dfAmVGRexORMWutS6Yrv/9IRj0i5wmph+Y YFUuk5jbrrDuChF7jB/ZiqHikp//LAdWcCjhTiNf7kOdz24jcAxhRyueckjLLjy7 Ht8JRiFq7VW5GFoLfjMHxGsYdBG/Fgjy6pML1rQ664YGJn/eq+lbWJZJGbzqnNiN 2HOBPi4oIbgYxbW3KId5sIX5Isg78p9lrID/KbyL5jjoTIqJap9+CBrTUkirP34= =cPY2 -----END PGP SIGNATURE-----