Verify the ISO
After downloading, it’s important to verify the ISO file. Verification confirms that the file was not corrupted during download and has not been maliciously tampered with.
Why Verification Is Needed
- Data errors can occur during network transfer, corrupting the ISO file
- A corrupted ISO may cause installation failures or system instability
- If obtained from an unofficial source, verification confirms the file hasn’t been tampered with
SHA256 Verification
SHA256 verification is the most basic integrity check. It works by comparing the file’s hash value to confirm whether the file is intact.
Obtain the Official Checksum
On the Ubuntu download page or mirror site directory, find the SHA256SUMS file:
https://releases.ubuntu.com/26.04/SHA256SUMSThe file contents look like this:
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 *ubuntu-26.04-desktop-amd64.isoVerify on Linux / macOS
# Calculate the SHA256 hash of the downloaded file
sha256sum ubuntu-26.04-desktop-amd64.iso
# Or directly compare against the official checksum file
sha256sum -c SHA256SUMS 2>/dev/null | grep ubuntu-26.04-desktop-amd64.isoIf the output shows OK, the file is intact.
Verify on Windows
Open PowerShell and run:
Get-FileHash .\ubuntu-26.04-desktop-amd64.iso -Algorithm SHA256Compare the output hash value character by character with the value in the official SHA256SUMS file.
GPG Signature Verification
GPG signature verification goes one step further than SHA256 — it not only verifies file integrity but also confirms that the checksum file itself was genuinely published by Ubuntu.
Download the Signature File
wget https://releases.ubuntu.com/26.04/SHA256SUMS
wget https://releases.ubuntu.com/26.04/SHA256SUMS.gpgImport the Ubuntu Signing Key
# Fetch the signing key from the Ubuntu key server
gpg --keyid-format long --keyserver hkp://keyserver.ubuntu.com --recv-keys 0x46181433FBB75451 0xD94AA3F0EFE21092Verify the Signature
gpg --keyid-format long --verify SHA256SUMS.gpg SHA256SUMSLook for the following key information in the output:
gpg: Good signature from "Ubuntu CD Image Automatic Signing Key"If you see Good signature, it means the SHA256SUMS file was genuinely signed by Ubuntu and can be trusted.
Note: You may see a warning:
WARNING: This key is not certified with a trusted signature!This is normal — just confirm that the key fingerprint matches the one officially published by Ubuntu.
Final ISO Verification
After confirming the signature is valid, verify the ISO with the authenticated SHA256SUMS file:
sha256sum -c SHA256SUMS 2>/dev/null | grep ubuntu-26.04-desktop-amd64.isoWhat to Do If Verification Fails
If verification does not pass, possible causes and solutions:
- Incomplete download: Re-download the ISO file, preferably using a tool that supports resume
- Mirror sync issue: Try downloading from a different mirror site or the official source
- File tampered with: If obtained from an unofficial source, be sure to re-download from an official or trusted mirror
Once verification passes, you can proceed to create a bootable USB drive.