> ## Documentation Index
> Fetch the complete documentation index at: https://docs.archil.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify Linux downloads

> Verify the authenticity and integrity of an Archil Linux release before installing it.

Archil publishes a signed SHA-256 checksum manifest for every signed Linux release. Use it to verify a downloaded DEB, RPM, or musl binary **before** installing or running it.

This procedure verifies that an artifact matches the release signed by Archil. It does not replace your normal review of the release version.

## Normal install or manual verification?

For a normal installation, use the convenience installer:

```bash theme={null}
curl -fsSL https://archil.com/install | sh
```

The convenience installer is the standard installation path. If you want to verify a versioned artifact before executing it, follow the manual OpenPGP signature and checksum procedure below.

## What you need

* `curl`
* `gpg` (GnuPG)
* `sha256sum` (supplied by GNU coreutils or BusyBox)

The commands below use a temporary GnuPG keyring and do not change your normal GnuPG configuration.

## Trust Archil's release signing key

Archil's production Linux release signing-subkey fingerprint is:

```text theme={null}
075082A64956DDB6281A08A827A9B35E790F664A
```

Before trusting a downloaded certificate, confirm that its fingerprint matches the value above. This documentation page is independent from the S3 release bucket.

## Archil Linux release public certificate

The following is Archil's public release certificate. Confirm that its fingerprint matches the value above before using it to verify a release.

```text theme={null}
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGpZOQ8BEADCz/oM30v+wqE0AJBo3zrPG29s5WmAt6iZA+2MC1JMN60EPlfV
TE5rBNvwJ6LbR1OaWNPVrwAvcPAHj2n1+bQI0ACuh7iRrcLh5670qLxluod1vJO8
+//8RzzSV4x+SEU6liYX+ncR0OlT1OyeJovQOmtc+yR2iIKf5tnUOww6DrO/JjYY
QRG5M27eGHl4n3cZUbzfC46Arup2oFI4hMYXcO21EKwzVxAOX1V9193/1hvqSeCy
BMT2F8U/dz7sHDQl3uutkSi71QmVc6y3FrcZGtF8BPXOOKqA/Y1CXCgEymmzIMy9
S8sxX/9Zmw6d1P0sOiz4G6vgGEFXS0d/lf/Qkmv6NewHCDFFbrWm3PnkgBF6weKA
irSSrFxcaPR4mrfXJaSw6ZYznfLDsIFQqd8ixRjQO64jhrNgk3QxEQ5ix/P7krE0
0WoIhZWNoUcM3GuWC5cEFDIop/Y76+XQRvvCzm4xBVnLiRAeQ+emvSmFDPmMZumn
lOJKvCHNX5UhJM9BgpsRdUhYIYsMSSzlf18UfyPFROIPkgGaZAiz9EgtROtKeKNS
xQyrfz9fVVJZNhXQ20GxYQBlv1KiLCoolVCW5+IRxS1kQjd8LvMdB1ANE26KSBo5
O7EozzjbU1CwLerJkX41sBD9tBQWCcmEJfSc9hcPnkBHbxZPK0WYw2SfNwARAQAB
tCtBcmNoaWwgTGludXggUmVsZWFzZXMgPHNlY3VyaXR5QGFyY2hpbC5jb20+iQJz
BBMBCABdFiEEexRMpLwXJLDlcvF7+t6vSq4R2tAFAmpZOQ8bFIAAAAAABAAObWFu
dTIsMi41KzEuMTIsMCwzAhsBBQkB4TOABQsJCAcCAiICBhUKCQgLAgQWAgMBAh4H
AheAAAoJEPrer0quEdrQhA0QALdizU5X0v/2/V2m8NdrIW7sI3/J/w6UdRzuTkGT
u8Q1rK3oVHcQUmETlnqCw3YFq632cZdBtl1CPIbwIx8sn+Hz0d3nFji/9PjK+nLD
FJXzHaD5hiLZ9QPH1U20jU5ogXx2cWUuI5geGGcoQLJOGyt1tjnCRCAaSD+0qb0c
vkXvP5dxgpSY3WRyhH/LOEf0ZEsSjwiQkmpf/Bl7fF6gBjpuKRJHqRN32ui6pDBw
dO24WXO422jBUQvjWVABnErAhsF9z0IF/4WQmy1j5cluhxLGuwKu/RIl6M+U/c2B
BKfDs1lH0vB+mlyg/Wvsl0QCqpldHNT5mMBgXbwDJeSn+WQYTTvur2IXOcxbwv+k
hBVCyiFufpkT88FTLLjKCZA/tiu9UWZEiTOG9C+fJV1zo0yqLTw+XvnVm/kMgixs
vIKams+HWGH641Fd+M3NbFTvhWm30SmEYXAJ7kQUGSvDPKCxHNCrxzxSAdWVWOFw
XiULzcyRPi0+/Hgccr3aFTiN+fRTfmiAVawuyobkSzwhSXsSAFffyegZ70heKd4E
dOc5f88X9yr7yM9u92meNtK6Y4jZ0JYMmPaUJzFFxIDwxiqlch48805cfwvOYiA6
Ru5pDoxvzwWBMUjvQryqGESl8vKd4As21H5FUrPLVxE8MGDdDzphe571hxPL5yKO
pAHuuQINBGpZOTwBEAC0kVgelpyJGSB7/+QRiZuS8pOgGBKZZw2XWaoxqWADky9S
tjTEMQsa4PoGWsmaGyiDoY8T4vvqQbHXYaDctVpWP8cvt1kdg9mVGSougyzr7sbF
1YyMUpINIEpSwFLauhzHz/SatPrM4XPbulkm+AHpUcOsZdm2hy55tYCQkwtDiZB/
0Oi/qbNYHV9f96fpJePgfU0Jg2wC55r2Mhi70SsF77lJV0hGbwNmIgIqBjs/6eDJ
q34VSS2A7TFeIyCRyyXfqCNX7cmMNCuxORgygzAJCCaTWzf2MAgSszU1Vm5mR4We
7l4c0zlZVQ2ajG7R2u1gU9Kc+JqBpnhyxsrihUoNAa4a96sYY+xxmc4zZd1w4GNg
fQ7OxP+Mj09Tn3QCcDWJ7QiBvwq8C5VwWqmJjvZm133xb2U7LUaqHbjZ6xibl4rs
qaywFfn+eOllbFi2MI3Ik/ysVj8V0j9TOPrhq6PGo3rIpQe0qMovVa5DgM1n2uYU
YxwJPMGkSnwFOQ4PkrucMra5Kyl2A5VObRvKljnBtvdUHgpTzTPhP/FNUNAWUZHu
s1v3QZRlCElWlXL9YS9wJ6Omy+5mWxAdv/OrGQxzkiWIwpVdU4e/pXEy+F8u52l+
dJ6APlARCnIb2P1ts6q78zsxTAIDvdIwYvUuIGDYVcdjP0ol0CSdgllErMF/ZwAR
AQABiQSOBBgBCABCFiEEexRMpLwXJLDlcvF7+t6vSq4R2tAFAmpZOTwbFIAAAAAA
BAAObWFudTIsMi41KzEuMTIsMCwzAhsCBQkB4TOAAkAJEPrer0quEdrQwXQgBBkB
CAAdFiEEB1CCpklW3bYoGgioJ6mzXnkPZkoFAmpZOTwACgkQJ6mzXnkPZkphfA//
Yz2BxmKU0zZp5pWVarHLfPxMbcVL0qFMdEvEPfhKA7B6eBAoygwFKjEuSD5jLHKE
E0k0Td6XtvVcaC9NQCskkRFZtDxlSz+eY1fJRrFaCwiwnlxT8fsd89nsvMhwWn0Q
bi7DMvf0aAK9cpG2FeNwcd9i4RdyPwRGCAsDj1UA6bEMoDL/eaT2vImloSlGk0BL
bGsHpj5PJ1kLj4yGq27z3Gh+uTukWbmJuvy8vxlMolpMpXCdBFgyvIGAlXy9q3Hl
GeziPkftVQ8oCW9bmUiZVaYnhLJgoxq8gH0HQI4NA9+JaUg0QV5ylE1EyUk9NDWI
sKkF98ia4hpcUHxs1JjEo4vpJHolFiVxcZbARIDCyoO3wIUkWH8FE7xlhSsFRSx4
+IpAYfCRRdG2Za24y9j4CcM2O0LXni+/8LvNt4D56nfB5T4m33Ds4nFV0Sr55ZbU
0RdJFSmxO0OHGjt3qDTfvYabdtv3xyoIL1XhZ4Yk2xLUXONs5UyphdenAvbXipkW
LYBRQOnINhFI7K3bBBibjKw5Z651AW8x1e+eAgOTZddF/cQwF2bwEoJfDCvF2ctr
3h0fjJD3Awt1oNG2EWKHTFKH82ZYjdfoiQnUYJO/f8iXj+M3WcuZghhKMz5XJLv1
Eu/oRuW9k25lqm/6Og3tB6mFFQgwYEC1PLc/xFiu8mYieRAAi3nlcDnXpv/TAL1a
Pa49wT8KEBWp/rgqzbEjieZq2IZn1XmgcIaR4e4Ei7WmIcZR7Tgzq+0mjodUqCb4
g0VJXrwyG2r9tBhCfn5BYcABfpUC2cLqVQWRBO623njV0GHZk/UXwimk/bTJpKCY
0+JJ+QzQ3HeAxWDZGRCI7TI+CxH/8hGtp+TxtbvGwLkL4RvJBlLXXHTY9IXBiLmT
9Fln2YgwY9AFKLaCD9A6UrPq/QuImgUTLJCPfRbu2oLnjuolP0SiMard/nF20BFz
4W7DVleNo0zm56n+QY6kMvkLLUH9aLPrDi/iIahN1kKztfK5XCYDEzPqTmgYoVlU
p772+AA33toxxj7tavf8yACSNVUicXUA5wP2+xoDi/3vOz1ORrgJpZdSqlU9+fzq
NVYippYkslYf1bGQdLpajQunOZpx37vyDqVliE1N9/djPn0SvTdYd/tfg0E+WAMH
g0L4kPlzkPcswZVrNqxlcA0dsqV61UtFSGXmNfLd5Plg+OxtWoh+iWqnQ3QJ/EsW
iymXJb12hpj4RPvIV2vgllRytvfBjct78D7sTYflEOUKTV0pStg6IhiTm2LxJm60
bOXxYVKzhuDRBM8UP3KlShryLTLntPof7hHsTHsB15DlCsEIMfTTTuKIRoHSf3dU
YNtC4jeY0l42wAa6kB9lPmUVAHI=
=pX2j
-----END PGP PUBLIC KEY BLOCK-----
```

## Choose a release and artifact

Choose the exact version and filename you intend to install. Signed Linux artifacts and their verification metadata are published under `https://s3.amazonaws.com/archil-client/pkg/`.

To select the version currently used by the production install channel, read its `latest` pointer:

```bash theme={null}
curl --fail --location https://s3.amazonaws.com/archil-client/pkg/latest
```

The `latest` pointer is mutable and is **not** authenticated. Use it only to choose a version to download; the signature and checksum steps below verify the artifact. For a reproducible installation, record an explicit version instead of relying on `latest`.

For example, if the release includes `archil_0.8.21-123_amd64.deb`, use `0.8.21-123` as `VERSION`:

```bash theme={null}
VERSION="0.8.21-123"
BASE_URL="https://s3.amazonaws.com/archil-client/pkg"
ARTIFACT="archil_${VERSION}_amd64.deb"
```

Use the exact filename listed in the release. The common artifact names are:

| Platform            | Artifact name                       |
| ------------------- | ----------------------------------- |
| Debian/Ubuntu AMD64 | `archil_<version>_amd64.deb`        |
| Debian/Ubuntu ARM64 | `archil_<version>_arm64.deb`        |
| RPM AMD64           | `archil-<rpm-version>.x86_64.rpm`   |
| RPM ARM64           | `archil-<rpm-version>.aarch64.rpm`  |
| musl AMD64          | `archil-linux-musl-amd64-<version>` |
| musl ARM64          | `archil-linux-musl-arm64-<version>` |

For RPMs, use the exact filename from the release. Pre-release versions can have a different RPM-safe version string.

## Download the artifact and verification files

Create a clean working directory and download the package, checksum manifest, detached signature, and public certificate for the **same version**:

```bash theme={null}
mkdir "archil-verify-${VERSION}"
cd "archil-verify-${VERSION}"

curl --fail-early --fail --location --remote-name-all \
  "$BASE_URL/$ARTIFACT" \
  "$BASE_URL/archil_${VERSION}_SHA256SUMS" \
  "$BASE_URL/archil_${VERSION}_SHA256SUMS.sig" \
  "$BASE_URL/archil_${VERSION}_linux_release_signing_key.asc"
```

Each signed release includes these verification files:

| File                                             | Purpose                                                             |
| ------------------------------------------------ | ------------------------------------------------------------------- |
| `archil_<version>_SHA256SUMS`                    | SHA-256 checksums for the six Linux artifacts.                      |
| `archil_<version>_SHA256SUMS.sig`                | ASCII-armored detached OpenPGP signature for the checksum manifest. |
| `archil_<version>_linux_release_signing_key.asc` | Public certificate for the Linux release signing key.               |

If any download fails, stop. In particular, we recommend not to install an artifact when its checksum manifest, signature, or certificate is unavailable. We suggest not to mix files from different versions or release channels. If the verification files for a release are unavailable, contact [support@archil.com](mailto:support@archil.com).

## Verify the public key and checksum signature

Import the downloaded certificate into a temporary keyring. The first check confirms that the certificate contains Archil's expected signing-subkey fingerprint; the second confirms that this exact key signed the checksum manifest.

```bash theme={null}
EXPECTED_FINGERPRINT="075082A64956DDB6281A08A827A9B35E790F664A"

export GNUPGHOME="$(mktemp -d)"
trap 'rm -rf "$GNUPGHOME"' EXIT
chmod 700 "$GNUPGHOME"

gpg --batch --import "archil_${VERSION}_linux_release_signing_key.asc"

if ! gpg --batch --with-colons --fingerprint --list-keys \
  | awk -F: -v expected="$EXPECTED_FINGERPRINT" \
    '$1 == "fpr" && toupper($10) == toupper(expected) { found = 1 } END { exit !found }'; then
  echo "The downloaded certificate does not contain Archil's expected signing fingerprint." >&2
  exit 1
fi

if ! gpg --batch --status-fd 1 --verify \
  "archil_${VERSION}_SHA256SUMS.sig" \
  "archil_${VERSION}_SHA256SUMS" 2>/dev/null \
  | awk -v expected="$EXPECTED_FINGERPRINT" \
    '$1 == "[GNUPG:]" && $2 == "VALIDSIG" && toupper($3) == toupper(expected) { found = 1 } END { exit !found }'; then
  echo "The checksum manifest did not pass Archil's expected signature validation. We recommend not installing the artifact." >&2
  exit 1
fi
```

<Warning>
  If either check fails, we advise not to install or run the artifact. Delete the downloaded files and obtain them again only from the canonical release location.
</Warning>

## Verify the downloaded artifact

Extract the one expected checksum entry, then verify your downloaded artifact against it:

```bash theme={null}
if ! CHECKSUM_LINE="$(awk -v artifact="$ARTIFACT" \
  '$2 == artifact { count++; line = $0 } END { if (count != 1) exit 1; print line }' \
  "archil_${VERSION}_SHA256SUMS")"; then
  echo "Expected exactly one checksum entry for $ARTIFACT." >&2
  exit 1
fi

if ! printf '%s\n' "$CHECKSUM_LINE" | sha256sum -c -; then
  echo "Checksum verification failed. Do not install or run $ARTIFACT." >&2
  exit 1
fi
```

The command must print:

```text theme={null}
<artifact name>: OK
```

If it prints `FAILED`, reports that the artifact is missing from the manifest, or produces no `OK` line, we recommend not installing or running the file.

## Install after verification

Run only the command applicable to your verified artifact:

```bash theme={null}
# Debian/Ubuntu
sudo apt install ./$ARTIFACT

# RPM-based distributions
sudo dnf install ./$ARTIFACT

# musl binary, for example Alpine
sudo install -m 0755 "$ARTIFACT" /usr/local/bin/archil
```

## Clean up

Remove the temporary keyring when you are finished:

```bash theme={null}
rm -rf "$GNUPGHOME"
unset GNUPGHOME EXPECTED_FINGERPRINT
```

## Key rotation and security notices

Before a planned signing-key rotation, Archil will publish the replacement fingerprint and retain the prior fingerprint during a documented overlap. If you suspect a signing key has been compromised, we advise not to install new artifacts until Archil publishes a security notice and replacement verification instructions through its documentation. Report suspected security issues to [security@archil.com](mailto:security@archil.com).

## Scope

This page covers versioned, signed Linux releases only. It does not cover macOS, Windows, package-repository signing, Sigstore or Cosign attestations, or the unversioned `https://archil.com/install` script.
