This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-tomcat-apache-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 19:31:34 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 31a01249012a2a85761d3c3aacaebd93113fb0bc * md5sum f0b504cdc67c5511c5eba0af2fe84c42 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXZgJAAoJEIXCXpWhbrlNTKAIAN6Ysl6gnb9cZY5hEANa2+XI h1glwy92itPoy7969DfkzmLGz8dZE46s0sAVq3Jb5vS98oYC2JhG9RGlEt4Dk/QS UYxbRCBqEvHcuHEBFyhrRyC9UvptXKVcOQABBMjHJ9f8ho2euRhuY6K6WC2hh5eo nL5zH6gUcD2FkT1N/haFapzkhV/82sdNhQGVEZgtoc6zqOakUr0XGoPSpvGNmT+M 8NP+C8P+K5Z+ctvQ0IA4YTru2SLWUP7kiT3OlxmJjhHrK447KgRBqPZ5hgnOBs59 +IqleZKvmaiBEnYHba7nYGKsKKuptJdyT6Cb0Poy9AnH+lXxYZPc7yFl8IXpgjE= =q8jy -----END PGP SIGNATURE-----