http://wikipewt4n75trifcse2ggaieot27svognl7idu6xmmqn37kf64rvsyd.onion/index.php/Verifying_PGP_signatures
This is OK and means that, for all intents and purposes, the signature matches the file. Command line Type gpg with the name of the signature file and press <ENTER>. If the package file is not in the same directory, or if the name of the signature file is mismatched, you will be prompted for the name of the package file.