This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-icescrum-12.1-squeeze-i386-xen.tar.bz2.sig gpg: Signature made Tue Jun 4 21:44:08 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 8e348746638271b4ed8aa1a996628177117d99f1 * md5sum 22090f5005b85b446025c8d7b3092d38 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJRrl+VAAoJEIXCXpWhbrlNXogH/3ZDEXyUC06305m/CNEW0X7q b4FpKvQEuO77rApGjNlZK9ZG+YhrVZCj0+rMGKJYxz0cItrHxSGVKoiR8voumNvL cgNRCNLsjoeP/TT7e5BBR68kPBQiilD1kHlOihSms9LmwktKAMDtUve7anZf3c7P zxdwpLM2NU0L5JZbxMzSCrzxNYQtz0dv0wpuSlb5D6Oc/dP444uPAbJap/eYX+dj EiaLwZTOe3ghOq7uSmlyfU/54Dqo42z6sjcCzRs8Q7B++Ix/RcVktfUh+GArYuTp bCaPndqbLl1A76uxbnA+ZMFswNn3SfPKHhgJ6UqNoZUu+ARmM4X7Ag5Gxt9UUWo= =StUR -----END PGP SIGNATURE-----