Nirmion
HelpLog in Find a tool

Security & Privacy · THE NO-PANIC PLAN

Verify an Ubuntu ISO with its signed SHA-256 checksum

A matching checksum is meaningful only when the expected checksum comes from a trusted source. For Ubuntu installation media, Canonical publishes a SHA-256 manifest and a detached GPG signature; verify the signing key and manifest first, then compare the downloaded ISO with the signed manifest. This guide covers Ubuntu ISO images, not third-party software or every cloud image format. Nirmion's Hash Verifier can compare a local file with the expected digest in your browser, but it cannot establish that the checksum or signing key is authentic. Never skip the GPG verification step or run/flash an image after a mismatch.

MISSION Help a user verify that a downloaded Ubuntu installation image matches the checksum in an authentic Ubuntu-signed manifest before using it.

Verify the Ubuntu image before installing it

THE REAL-WORLD BIT

What happens outside this browser tab?

Choose the exact Ubuntu release and architecture; obtain the image and checksum/signature files from Ubuntu's release sources; establish trust in the Ubuntu image-signing key; verify the checksum manifest's signature; compare the ISO bytes to the authenticated SHA-256 entry; and stop or retry safely if any check fails.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Select the exact Ubuntu release and image

    Start at Ubuntu's official download or release page and choose the release, edition and computer architecture you actually intend to install. Confirm the exact ISO filename, version and architecture shown by the official release source; do not guess from an old article or a similarly named mirror file. Note the release identifier and filename in a private verification record. The matching SHA256SUMS manifest is specific to a release's published images, so an image from another release or architecture will not match the intended entry. If the file is for Ubuntu Cloud Images rather than installation media, stop here and use that image type's own current verification instructions instead of applying the ISO steps blindly.

  2. 02

    Get the Ubuntu signing key and establish its identity

    Follow the current Ubuntu Security documentation to obtain the Ubuntu Image Signing public key or keyring used for installation media. Before relying on it, validate the key identity through a trust path you already have: compare its full fingerprint with Ubuntu's current published fingerprint from a separately trusted source, or compare it with the Ubuntu signing keys on a trusted installed system. A key downloaded from the same location as an unverified checksum file is not, by itself, proof of identity. Stop if the fingerprint is missing, differs, or you cannot establish how the key is trusted; do not use the key to certify a manifest until this check passes. Record the fingerprint and how you verified it, without storing a private key.

  3. 03

    Verify the signed SHA256SUMS manifest

    For the selected release, download the SHA256SUMS file and its SHA256SUMS.gpg detached signature from the Ubuntu release source listed in Canonical's current image-verification instructions. With the verified Ubuntu image-signing keyring available, run the documented GPG verification (for example, `gpgv --keyring ./ubuntu.gpg ./SHA256SUMS.gpg ./SHA256SUMS`). Confirm that GPG reports a valid signature from the expected Ubuntu image-signing key. This authenticates the manifest under that key; it is a different check from comparing the ISO's hash. If GPG reports a bad, missing or untrusted key/signature, stop and resolve the trust issue rather than treating a matching digest as proof.

  4. 04

    Compare the downloaded ISO with its authenticated digest

    Locate the exact ISO filename in the verified SHA256SUMS manifest and copy the complete SHA-256 value for that file. Open the ISO with Nirmion's Hash Verifier (tool 29833) or use a trusted local SHA-256 utility; choose the SHA-256 algorithm and compare the complete computed digest with the manifest entry, ignoring letter case only. Confirm that the tool processed the intended downloaded ISO, not a similarly named file or a text string. The Nirmion tool's processing is browser-local, but its result only performs the byte comparison: it cannot verify the GPG signature, release identity, signing-key fingerprint or publisher. Keep the manifest/signature check as a required prior step.

  5. 05

    Decide from both checks and preserve the verification record

    Proceed only when the signing key's identity is established, the manifest signature is valid, and the exact ISO's SHA-256 digest matches its entry. If the digest differs or the expected filename is absent, do not install or write the image to a device. Delete or quarantine the suspect copy, download the exact ISO and associated files again from Ubuntu's official release source, and repeat the entire verification; if it still fails, stop and report it to the official Ubuntu support or release channel. A matching digest proves the downloaded bytes agree with the signed manifest, but it does not independently guarantee that software is bug-free or appropriate for every use. Record the Ubuntu release, architecture, filename, manifest signature result, key fingerprint, digest result and check date so another person can reproduce the check.

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-05