Fedora keeps you safe
Learn how to verify your downloads
Verify your download
Once you have downloaded an image, be sure to verify it for both security and integrity.
By calculating the image’s checksum on your own computer and comparing it to the original checksum, you can verify the image has not been tampered with or corrupted. Images are also gpg signed with Fedora keys to demonstrate their integrity.
Click the verify button to get instructions tailored for your download.
Verify with CHECKSUM files
If your download comes with a CHECKSUM file, follow these easy steps to verify your image for both security and integrity.
Import Fedora's GPG key(s)
curl -O https://fedoraproject.org/fedora.gpg
List Fedora's GPG key(s)
gpg --with-fingerprint --show-keys --keyid-format long fedora.gpg
You can verify the details of the GPG key(s) below.
Verify the CHECKSUM file is valid
for checksum in *-CHECKSUM; do gpgv --keyring ./fedora.gpg "$checksum"; done
Verify the checksum matches
sha256sum -c *-CHECKSUM
If the output states that the file is valid, then it's ready to use!
Package signing keys
Learn how Fedora uses package signing to help protect you.
Each stable RPM package published by the Fedora Project is signed with a GPG signature. By default, dnf
and the graphical update tools will verify these signatures and refuse to install any packages that are not signed or have bad signatures. You should always verify the signature of a package before you install it. These signatures ensure that the packages you install are what was produced by the Fedora Project and have not been altered (accidentally or maliciously) by any mirror or website that is providing the packages.
Current GPG keys
Fedora Rawhide
rsa4096/105EF944 2024-02-12
B0F4950458F69E1150C6C5EDC8AC4916105EF944
B0F4 9504 58F6 9E11 50C6 C5ED C8AC 4916 105E F944
a75bfc75bf3569a0280bd78d98a07de7ef3d7579b9dc3cfb270542c6._openpgpkey.fedoraproject.org
Fedora 41
rsa4096/E99D6AD1 2023-08-08
466CF2D8B60BC3057AA9453ED0622462E99D6AD1
466C F2D8 B60B C305 7AA9 453E D062 2462 E99D 6AD1
4708da3c8d2e316f3321396cfb18e064f90a361490165d2723a63730._openpgpkey.fedoraproject.org
Fedora 40
rsa4096/A15B79CC 2023-01-24
115DF9AEF857853EE8445D0A0727707EA15B79CC
115D F9AE F857 853E E844 5D0A 0727 707E A15B 79CC
4d0cd6e4349d5979387749daf5995f20d0de7f7b2fdfdc76d7eb21a1._openpgpkey.fedoraproject.org
Fedora 39
rsa4096/18B8E74C 2022-08-09
E8F23996F23218640CB44CBE75CF5AC418B8E74C
E8F2 3996 F232 1864 0CB4 4CBE 75CF 5AC4 18B8 E74C
48cb71516f035e33db6249d81d145d8b9198da654fbfbcf16c06104d._openpgpkey.fedoraproject.org
EPEL 10
rsa4096/E37ED158 2023-12-12
7D8D15CBFC4E62688591FB2633D98517E37ED158
7D8D 15CB FC4E 6268 8591 FB26 33D9 8517 E37E D158
1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org
EPEL 9
rsa4096/3228467C 2021-09-07
FF8AD1344597106ECE813B918A3872BF3228467C
FF8A D134 4597 106E CE81 3B91 8A38 72BF 3228 467C
1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org
EPEL 8
rsa4096/2F86D6A1 2019-06-05
94E279EB8D8F25B21810ADF121EA45AB2F86D6A1
94E2 79EB 8D8F 25B2 1810 ADF1 21EA 45AB 2F86 D6A1
1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org
Obsolete GPG keys
Found a security bug?
Please take a moment and let us know. Learn how on our wiki page.