Skip to content
Start of main content

Fedora keeps you safe

Learn how to verify your downloads

Verifiche il file discjariât

Une volte discjamade une imagjin, viôt di verificâle sedi pe sigurece e che pe integritât.

Calcolant la sume di control de imagjin sul to computer e confrontantle cun chê origjinâl, tu puedis verificâ che la imagjin no vedi subît modifichis o che e sedi corote. Lis imagjinis a son ancje firmadis cun pgp cu lis clâfs di Fedora, par dimostrâ la lôr integrât.

Fâs clic sul boton di verifiche par otignî istruzions smiradis pal to discjariament.

Verify with CHECKSUM files

If your download comes with a CHECKSUM file, follow these easy steps to verify your image for both security and integrity.

  • Impuarte lis clâfs GPG di Fedora

    curl -O https://fedoraproject.org/fedora.gpg
  • Liste des clâfs GPG di Fedora

    gpg --with-fingerprint --show-keys --keyid-format long fedora.gpg

    Tu puedis verificâ i detais des clâfs GPG chi sot.

  • Verifiche che il file CHECKSUM al sedi valit

    gpgv --keyring ./fedora.gpg *-CHECKSUM
  • Verifiche che la sume di control e corispuindi

    sha256sum -c *-CHECKSUM

Se la jessude e indiche che il file al è valit, alore al è pront di doprâ!

Package signing keys

Learn how Fedora uses package signing to help protect you.

Each stable RPM package published by the Fedora Project is signed with a GPG signature. By default, dnf and the graphical update tools will verify these signatures and refuse to install any packages that are not signed or have bad signatures. You should always verify the signature of a package before you install it. These signatures ensure that the packages you install are what was produced by the Fedora Project and have not been altered (accidentally or maliciously) by any mirror or website that is providing the packages.

Clâfs GPG atuâls

Fedora Rawhide

id: rsa4096/A15B79CC 2023-01-24

Fingerprint: 115DF9AEF857853EE8445D0A0727707EA15B79CC

DNS OpenPGPKey: 4d0cd6e4349d5979387749daf5995f20d0de7f7b2fdfdc76d7eb21a1._openpgpkey.fedoraproject.org

Fedora 39

id: rsa4096/18B8E74C 2022-08-09

Fingerprint: E8F23996F23218640CB44CBE75CF5AC418B8E74C

DNS OpenPGPKey: 48cb71516f035e33db6249d81d145d8b9198da654fbfbcf16c06104d._openpgpkey.fedoraproject.org

Fedora 38

id: rsa4096/EB10B464 2022-02-08

Fingerprint: 6A51BBABBA3D5467B6171221809A8D7CEB10B464

DNS OpenPGPKey: 490cba59bda7a7f15781835ffff717f123dd00297312f7a03b74b9a7._openpgpkey.fedoraproject.org

Fedora 37

id: rsa4096/5323552A 2021-08-10

Fingerprint: ACB5EE4E831C74BB7C168D27F55AD3FB5323552A

DNS OpenPGPKey: 5dde64bce74cf052cba5361957e81b0fe47a044c63d2a7315cdac7cd._openpgpkey.fedoraproject.org

Fedora 36

id: rsa4096/38AB71F4 2021-02-10

Fingerprint: 53DED2CB922D8B8D9E63FD18999F7CBF38AB71F4

DNS OpenPGPKey: 6e5f831105b72f261abfc06974c08b4ed718c650447d0b309b8658dd._openpgpkey.fedoraproject.org

Fedora 35

id: rsa4096/9867C58F 2021-02-04

Fingerprint: 787EA6AE1147EEE56C40B30CDB4639719867C58F

DNS OpenPGPKey: e27f1efe21ae589b7796e61af3ac4a4c1c2428615daca70d8f1c9e96._openpgpkey.fedoraproject.org

Fedora IOT

id: rsa4096/DBBDCF7C 2018-11-13

Fingerprint: C2A3FA9DC67F68B98BB543F47BB90722DBBDCF7C

DNS OpenPGPKey: 8b6135462c1d8c1a927b1a9eb1f47c2c1cde3429ae60ccd630d057ac._openpgpkey.fedoraproject.org

EPEL 9

id: rsa4096/3228467C 2021-09-07

Fingerprint: FF8AD1344597106ECE813B918A3872BF3228467C

DNS OpenPGPKey: 1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

EPEL 8

id: rsa4096/2F86D6A1 2019-06-05

Fingerprint: 94E279EB8D8F25B21810ADF121EA45AB2F86D6A1

DNS OpenPGPKey: 1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

EPEL 7

id: rsa4096/352C64E5 2013-12-16

Fingerprint: 91E97D7C4A5E96F17F3E888F6A2FAEA2352C64E5

DNS OpenPGPKey: 1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

Clâfs GPG passadis

Found a security bug?

Please take a moment and let us know. Learn how on our wiki page.