Skip to Content

Verify the ISO

After downloading, it’s important to verify the ISO file. Verification confirms that the file was not corrupted during download and has not been maliciously tampered with.

Why Verification Is Needed

  • Data errors can occur during network transfer, corrupting the ISO file
  • A corrupted ISO may cause installation failures or system instability
  • If obtained from an unofficial source, verification confirms the file hasn’t been tampered with

SHA256 Verification

SHA256 verification is the most basic integrity check. It works by comparing the file’s hash value to confirm whether the file is intact.

Obtain the Official Checksum

On the Ubuntu download page or mirror site directory, find the SHA256SUMS file:

https://releases.ubuntu.com/26.04/SHA256SUMS

The file contents look like this:

e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 *ubuntu-26.04-desktop-amd64.iso

Verify on Linux / macOS

# Calculate the SHA256 hash of the downloaded file sha256sum ubuntu-26.04-desktop-amd64.iso # Or directly compare against the official checksum file sha256sum -c SHA256SUMS 2>/dev/null | grep ubuntu-26.04-desktop-amd64.iso

If the output shows OK, the file is intact.

Verify on Windows

Open PowerShell and run:

Get-FileHash .\ubuntu-26.04-desktop-amd64.iso -Algorithm SHA256

Compare the output hash value character by character with the value in the official SHA256SUMS file.

GPG Signature Verification

GPG signature verification goes one step further than SHA256 — it not only verifies file integrity but also confirms that the checksum file itself was genuinely published by Ubuntu.

Download the Signature File

wget https://releases.ubuntu.com/26.04/SHA256SUMS wget https://releases.ubuntu.com/26.04/SHA256SUMS.gpg

Import the Ubuntu Signing Key

# Fetch the signing key from the Ubuntu key server gpg --keyid-format long --keyserver hkp://keyserver.ubuntu.com --recv-keys 0x46181433FBB75451 0xD94AA3F0EFE21092

Verify the Signature

gpg --keyid-format long --verify SHA256SUMS.gpg SHA256SUMS

Look for the following key information in the output:

gpg: Good signature from "Ubuntu CD Image Automatic Signing Key"

If you see Good signature, it means the SHA256SUMS file was genuinely signed by Ubuntu and can be trusted.

Note: You may see a warning: WARNING: This key is not certified with a trusted signature! This is normal — just confirm that the key fingerprint matches the one officially published by Ubuntu.

Final ISO Verification

After confirming the signature is valid, verify the ISO with the authenticated SHA256SUMS file:

sha256sum -c SHA256SUMS 2>/dev/null | grep ubuntu-26.04-desktop-amd64.iso

What to Do If Verification Fails

If verification does not pass, possible causes and solutions:

  1. Incomplete download: Re-download the ISO file, preferably using a tool that supports resume
  2. Mirror sync issue: Try downloading from a different mirror site or the official source
  3. File tampered with: If obtained from an unofficial source, be sure to re-download from an official or trusted mirror

Once verification passes, you can proceed to create a bootable USB drive.

Last updated on