# Verify checksum signature

**URL:** <https://forums.rockylinux.org/t/verify-checksum-signature/3302>\
**Category:** Rocky Linux Help & Support\
**Created:** [June 30, 2021, 12:59am UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302 "2021-06-30T00:59:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![maf](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/maf/32/1062_2.png) [@maf](https://forums.rockylinux.org/u/maf)\
**Post date:** [June 30, 2021, 12:59am UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302/1 "2021-06-30T00:59:44Z")

</div>

Hey guise, I downloaded the torrent and there’s CHECKSUM{,.sig} in it. Verifying with sha256sum is easy, e.g. `sha256sum -c CHECKSUM --ignore-missing` 😄

So how about verifying the signature with gpg2? If I do `gpg2 --verify CHECKSUM.sig CHECKSUM`, I get `Can't check signature: No public key`. Of course it hasn’t been imported to my keyring yet, cus I couldn’t find it anywhere 🤨

It’s always a good idea to verify downloads, especially binaries. It’s quite nice that the torrent includes the required data, tyvm

---

<div class="post-metadata">

**Author:** ![tcooper](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/tcooper/32/905_2.png) [@tcooper](https://forums.rockylinux.org/u/tcooper)\
**Post date:** [June 30, 2021, 5:41am UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302/2 "2021-06-30T05:41:19Z")

</div>

You can download the Rocky Infrastructure key which is used to sign the ISOs from the mirrors.

I believe it is the one named [RPM-GPG-KEY-rockyinfra](https://download.rockylinux.org/pub/rocky/RPM-GPG-KEY-rockyinfra).

Alternately, you can get the key from the [openpgp keyserver](https://keys.openpgp.org/search?q=BFC3D8F20D15F4FD46281D7FAA650F52D6C094FA).

---

<div class="post-metadata">

**Author:** ![maf](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/maf/32/1062_2.png) [@maf](https://forums.rockylinux.org/u/maf)\
**Post date:** [June 30, 2021, 10:26am UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302/3 "2021-06-30T10:26:56Z")

</div>

Thank you. This worked: `gpg2 --keyserver hkps://keys.openpgp.org --locate-keys 'infrastructure@rockylinux.org'`

---

<div class="post-metadata">

**Author:** ![hunter86\_bg](https://avatars.discourse-cdn.com/v4/letter/h/f08c70/32.png) [@hunter86\_bg](https://forums.rockylinux.org/u/hunter86_bg)\
**Post date:** [November 20, 2021, 9:56pm UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302/4 "2021-11-20T21:56:03Z")

</div>

Rocky 8.5 is signed with 7051C470A929F454CEBE37B715AF5DAC6D745A60 from the Release Engineering [infrastructure@rockylinux.org](mailto:infrastructure@rockylinux.org)

```auto
# gpg2 --verify CHECKSUM.sig 
gpg: assuming signed data in 'CHECKSUM'
gpg: Signature made 15.11.2021 (пн) 8:07:09 EET
gpg: using RSA key 7051C470A929F454CEBE37B715AF5DAC6D745A60
gpg: Good signature from "Release Engineering <infrastructure@rockylinux.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 7051 C470 A929 F454 CEBE 37B7 15AF 5DAC 6D74 5A60

# gpg2 --keyserver hkps://keys.openpgp.org --locate-keys 'infrastructure@rockylinux.org'
pub rsa4096 2021-02-14 [SCE]
      7051C470A929F454CEBE37B715AF5DAC6D745A60
uid [unknown] Release Engineering <infrastructure@rockylinux.org>

```

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 4:01am UTC](https://forums.rockylinux.org/t/verify-checksum-signature/3302/5 "2023-08-25T04:01:02Z")

</div>


