Checksum verification error message is mysterious

asked 2012-06-13 07:45:37 +0000

catharpins gravatar image

Hi, after I d/l Fedora-17-x8664-Live-KDE.iso, I d/l the Fedora-17-x8664-Live-CHECKSUM into the same directory. Then I followed the rest of the clearly documented directions in the Fedora 'Verify your ISO Download.'

Several errors occurred, and the log is here:

[root@mycomputer Downloads]# curl https://fedoraproject.org/static/fedora.gpg | gpg --import
gpg: directory `/root/.gnupg' created
gpg: new configuration file `/root/.gnupg/gpg.conf' created
gpg: WARNING: options in `/root/.gnupg/gpg.conf' are not yet active during this run
gpg: keyring `/root/.gnupg/secring.gpg' created
gpg: keyring `/root/.gnupg/pubring.gpg' created
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 24213 100 24213 0 0 12823 0 0:00:01 0:00:01 --:--:-- 14110
gpg: /root/.gnupg/trustdb.gpg: trustdb created
gpg: key 069C8460: public key "Fedora (15) <fedora@fedoraproject.org>" imported
gpg: key 3AD31D0B: public key "Fedora-SPARC (15) <fedora@fedoraproject.org>" imported
gpg: key A82BA4B7: public key "Fedora (16) <fedora@fedoraproject.org>" imported
gpg: key 10D90A9E: public key "Fedora Secondary (16) <fedora@fedoraproject.org>" imported
gpg: key 1ACA3465: public key "Fedora (17) <fedora@fedoraproject.org>" imported
gpg: key F8DF67E6: public key "Fedora Secondary Arch (17) <fedora@fedoraproject.org>" imported
gpg: key 22B3B81A: public key "Fedora (18) <fedora@fedoraproject.org>" imported
gpg: key 34E166FA: public key "Fedora Secondary Arch (18) <fedora@fedoraproject.org>" imported
gpg: key 217521F6: public key "Fedora EPEL <epel@fedoraproject.org>" imported
gpg: key 0608B895: public key "EPEL (6) <epel@fedoraproject.org>" imported
gpg: Total number processed: 10
gpg: imported: 10 (RSA: 9)

[root@mycomputer Downloads]# gpg --verify-files *-CHECKSUM
gpg: Signature made Thu 24 May 2012 10:27:03 PM PDT using RSA key ID 1ACA3465
gpg: Good signature from "Fedora (17) <fedora@fedoraproject.org>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: CAC4 3FB7 74A4 A673 D81C 5DE7 50E9 4C99 1ACA 3465

[root@mycomputer Downloads]# sha256sum -c *-CHECKSUM
sha256sum: Fedora-17-x86_64-Live-Desktop.iso: No such file or directory
Fedora-17-x86_64-Live-Desktop.iso: FAILED open or read
Fedora-17-x86_64-Live-KDE.iso: OK
sha256sum: WARNING: 20 lines are improperly formatted
sha256sum: WARNING: 1 listed file could not be read
[root@mycomputer Downloads]

The file i wanted to verify shows: OK. But there are two warnings at the end. In particular, I'd like to know what is going on in the sha256sum. Could someone help me with understanding what this is telling me?

Thanks & Cheers!


answered 2012-10-04 19:10:34 +0000

sha256sum: WARNING: 20 lines are improperly formatted

This warning comes from the GPG signature in the checksum file. It can be ignored. The GPG signature data is 20 lines of information sha256sum doesn't understand.

sha256sum: WARNING: 1 listed file could not be read

This warning is because the checksum file has two ISOs listed, you only have one of them (so it can't check the file you don't have).

