# How to fully verify iso download

**URL:** <https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285>\
**Category:** Rocky Linux Help & Support\
**Created:** [October 11, 2021, 8:35pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285 "2021-10-11T20:35:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![RL1000](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@RL1000](https://forums.rockylinux.org/u/RL1000)\
**Post date:** [October 11, 2021, 8:35pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/1 "2021-10-11T20:35:53Z")

</div>

Hi,

When I try and post my issue below, the forum site says:  
Sorry, new users can only put 2 links in a post.

I am not trying to put any links in the post, but the links in the text below are recognized as such, so I have to try and edit the links so they are not links. I tried to quote things but that didnt help.  
I am replacing https:// with lala- but this did not help either. Really frustrating when one cant ask a question because the site limits them.  
Anyways I will try editing things until I can post…

As per:  
[Verify checksum signature] - Another post in this forum whose link I had to chop out.

I would like to verify the iso.  
But I am getting stuck.  
So far what I have done is:

- Download the iso file: Rocky-8.4-x86\_64-dvd1.iso

- Download the CHECKSUM file

- Put them in a separate folder

- Run:

```auto

> gpg2 --keyserver lala-//keys.openpgp.org --locate-keys 'infrastructure@rockylinux.org'

```

Which gives me:

> gpg: key AA650F52D6C094FA: public key “Core Infrastructure [infrastructure@rockylinux.org](mailto:infrastructure@rockylinux.org)” imported  
> gpg: Total number processed: 1  
> gpg: imported: 1  
> pub ed25519 2021-05-17 [SC] [expires: 2023-05-17]  
> BFC3D8F20D15F4FD46281D7FAA650F52D6C094FA  
> uid [unknown] Core Infrastructure [infrastructure@rockylinux.org](mailto:infrastructure@rockylinux.org)  
> sub cv25519 2021-05-17 [E] [expires: 2023-05-17]

The next step is not documented (I cant find this in the forum nor the Download instructions) but I thought it should be:

gpg --verify CHECKSUM

But this gives me the error:

gpg: no valid OpenPGP data found.  
gpg: the signature could not be verified.  
Please remember that the signature file (.sig or .asc)  
should be the first file given on the command line.

What should be the next steps to completely verify a download?

Thanks ahead of time…

---

<div class="post-metadata">

**Author:** ![tjdoyle](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/tjdoyle/32/500_2.png) [@tjdoyle](https://forums.rockylinux.org/u/tjdoyle)\
**Post date:** [October 11, 2021, 9:08pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/2 "2021-10-11T21:08:21Z")

</div>

[https://docs.rockylinux.org/guides/installation/#verifying-the-installer-iso-file](https://docs.rockylinux.org/guides/installation/#verifying-the-installer-iso-file)

---

<div class="post-metadata">

**Author:** ![RL1000](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@RL1000](https://forums.rockylinux.org/u/RL1000)\
**Post date:** [October 11, 2021, 9:42pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/3 "2021-10-11T21:42:23Z")

</div>

Hi, I was aware of that page and had followed the instructions.  
This page does not include the step to verify the file using the signature.  
This page only shows how to compare the sha256 checksum of the iso with the checksum provided in the CHECKSUM file.  
IMHO I dont think this page’s section should be called " Verifying the Installer ISO File" since it does not verify the file using signature.  
I, like the post [Verify checksum signature] - Another post in this forum whose link I had to chop out, think it is important to verify as well.  
I am afraid to post links here but if you look at most distro’s verification instructions, including eg AlmaLinux, they show how to get a signature and verify.

---

<div class="post-metadata">

**Author:** ![tjdoyle](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/tjdoyle/32/500_2.png) [@tjdoyle](https://forums.rockylinux.org/u/tjdoyle)\
**Post date:** [October 11, 2021, 9:58pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/4 "2021-10-11T21:58:28Z")

</div>

Hi,

> [@Wrong ISO checksums on download page?](https://forums.rockylinux.org/t/wrong-iso-checksums-on-download-page/3271/4):
>
> I’ve verified also the CHECKSUM signature with aarch64$ gpg2 --verify CHECKSUM.sig CHECKSUM gpg: Signature made Mon 21 Jun 2021 12:47:55 AM CEST gpg: using EDDSA key BFC3D8F20D15F4FD46281D7FAA650F52D6C094FA gpg: issuer "infrastructure@rockylinux.org" gpg: Good signature from "Core Infrastructure \<infrastructure@rockylinux.org\>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs…

Based on the above, this works for me:

```auto
gpg2 --keyserver lala-//keys.openpgp.org --locate-keys 'infrastructure@rockylinux.org'
wget https://download.rockylinux.org/pub/rocky/8.4/isos/x86_64/CHECKSUM.sig
wget https://download.rockylinux.org/pub/rocky/8.4/isos/x86_64/CHECKSUM
gpg2 --verify CHECKSUM.sig CHECKSUM

```

---

<div class="post-metadata">

**Author:** ![RL1000](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@RL1000](https://forums.rockylinux.org/u/RL1000)\
**Post date:** [October 11, 2021, 11:37pm UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/5 "2021-10-11T23:37:38Z")

</div>

Thanks very much for that.  
I will try it out in the next day or so.

---

<div class="post-metadata">

**Author:** ![RL1000](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@RL1000](https://forums.rockylinux.org/u/RL1000)\
**Post date:** [October 12, 2021, 9:53am UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/6 "2021-10-12T09:53:44Z")

</div>

@ [tjdoyle](https://forums.rockylinux.org/u/tjdoyle), that worked great, thanks very much for your help.

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 4:04am UTC](https://forums.rockylinux.org/t/how-to-fully-verify-iso-download/4285/7 "2023-08-25T04:04:03Z")

</div>


