Nirmion
HelpLog in Find a tool

Security & Privacy · THE NO-PANIC PLAN

Record and verify a downloaded file's checksum

Use this workflow when you need a reproducible integrity check for a downloaded release, backup, dataset or other file. First establish where the expected digest came from; then compute the same algorithm over the original bytes, compare the complete values and document what was actually verified. A plain checksum comparison can detect a mismatch against a trusted reference, but cannot authenticate a publisher unless the reference itself is authenticated, and it does not determine whether a matching file is safe. Nirmion's Checksum File Generator and Checksum Verifier can help with local digest calculation and comparison; review each tool's current page and limits before relying on it.

MISSION Create a repeatable record of a downloaded file's digest, confirm it against an authenticated expected value and preserve the exact verification result without claiming a checksum proves safety or identity.

Verify a file checksum

THE REAL-WORLD BIT

What happens outside this browser tab?

Define the file and verification claim; obtain the artifact and expected digest from authoritative release material; authenticate the checksum manifest when a publisher signature is available; compute a digest over the complete original bytes; compare the full values using the same algorithm; stop on mismatch and save provenance, method and result for repeat review.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Decide what the record must prove

    Identify the exact file, why its bytes need checking, who published it and what decision depends on the result. Record the file's expected name, release or version, source page, download date and the digest algorithm the publisher specifies. A checksum match answers only whether the bytes you measured match a reference digest; it does not show that the reference came from the real publisher, that the file is safe, or that its contents are suitable. NIST's Secure Hash Standard describes digests as a way to detect changes, while its hash guidance treats cryptographic hashes as components in broader security uses. If authenticity matters, plan to authenticate the publisher's signed checksum or signature with a trusted key before comparing the file. (Sources 1, 4)

  2. 02

    Obtain the file and a trustworthy reference digest

    Download the file from the publisher's official release page and obtain the expected digest and algorithm from that release's published verification material. Prefer a signed checksum manifest and verify its signature using the publisher's documented key and fingerprint through a trusted channel; a checksum copied from the same untrusted download page can be changed alongside the file. Confirm the release, architecture, edition and exact filename match the artifact you chose. Ubuntu's verification tutorial illustrates the sequence of authenticating its checksum manifest and then checking the ISO; its Ubuntu commands and key details are specific to Ubuntu. If a signature cannot be verified or the digest provenance is unclear, record the limitation and do not describe the file as authenticated. (Sources 2, 3, 4)

  3. 03

    Compute the digest from the complete original file

    Keep the downloaded original unchanged and compute the publisher-specified digest over the complete file bytes. In PowerShell, Microsoft's Get-FileHash supports an explicit algorithm such as SHA256; on other systems use a maintained local utility appropriate to that operating system. Alternatively, Nirmion Checksum File Generator (tool 269) can calculate a digest from the file selected in the browser; review its page for current input limits and local-processing behavior before using it. Select the same algorithm as the expected value, avoid hashing a preview, extracted portion or renamed conversion, and note any error or unsupported format. A hash value is a fingerprint of those bytes; it does not scan the file for malware or repair corruption. (Sources 1, 2)

  4. 04

    Compare the full values and stop on any mismatch

    Compare the algorithm labels and every hexadecimal character of the computed digest against the trusted expected value, ignoring only formatting whitespace that the publisher's documented tool permits. Do not compare truncated snippets, mix SHA-256 with another algorithm, or assume a matching filename means the bytes match. Nirmion Checksum Verifier (tool 268) can compare the supplied expected and computed values; use it only after checking the algorithm and source yourself. A mismatch, missing file or unreadable result is a failed verification: do not install, open with elevated privileges or distribute the artifact. Re-download from the publisher's official source and recompute; if it still fails, consult the publisher's incident or support guidance. Ubuntu likewise directs users to treat a non-matching ISO as altered or incorrectly downloaded and fetch a fresh copy. (Sources 2, 3, 4)

  5. 05

    Save a reproducible verification record

    Record the original filename and version, file size if available, download URL, date checked, digest algorithm, full expected and computed digests, reference-manifest URL, signature-verification result and source of the trusted key or fingerprint, final comparison result, operator and tool or command used. Preserve enough detail for another person to repeat the check, but do not include private access tokens, confidential URLs or the file itself unless the receiving system is approved for it. NIST's hash guidance supports recording the algorithm and context; Ubuntu's example makes clear that authenticating the checksum manifest and comparing the artifact are separate checks. State precisely whether only a byte-for-byte digest comparison passed or the publisher's signature was also verified. This record is evidence of those checks at that time, not a guarantee of safety or future integrity. (Sources 1, 3, 4)

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-07