This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-otrs-13.0-wheezy-i386-vmdk.zip.sig gpg: Signature made Tue Oct 15 17:33:51 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 28ec9aa810d91344ec0d6114bd93500ba0da8ee9 * md5sum 7ebb10fdbc8852143807ea58f9c113e8 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXXx1AAoJEIXCXpWhbrlNBJ8IAMzy6U1eB4hfvj5WxkxL9AYT NqO3lPZX5ur2Pdd0BZPBNbDC2Iv4f5nmAnRlzrVLtJmM+7AGlMFEAyjiK9SX/k6q M+QiEUMcImX9i8vMKNqr2V15morPUG4GliKIz5jq4A1mq4vM2eac7BV532qMrZd3 9JXcuJaXRfAuCZaWrPwMEDe/AFN5CkswazSq7plkampaIgEJQQWkJ0xe7sWheK0e wAce4zrjihk2Eo6W9kvC7COeeuVMWWQ9avH5/7AyfhbkvVQEuJUJMyy7JbwI8WZC EVxmfxV6o+lQpWKVeEPBQKpY++qfTBuCL2IWUsAvquxFb726uGCWm9yXzFm5RSw= =0Y5q -----END PGP SIGNATURE-----