Skip to main content Start of main content

Fedora keeps you safe

Learn how to verify your downloads

校驗您的下載

在您下載映像檔以後,請務必校驗檔案的安全性與完整性。

透過在您的電腦上計算映像檔的校驗碼並與原始校驗碼比對,您可以確認映像檔未被篡改或損毀。此外,映像檔也使用 Fedora 金鑰進行 GPG 簽署,以確保其完整性。

點按驗証按鈕 取得為您的下載量身訂做的說明。

使用校驗碼檔案進行驗證

If your download comes with a CHECKSUM file, follow these easy steps to verify your image for both security and integrity.

  • 匯入 Fedora 的 GPG 金鑰

    curl -O https://fedoraproject.org/fedora.gpg
  • 列出 Fedora 的 GPG 金鑰

    gpg --with-fingerprint --show-keys --keyid-format long fedora.gpg

    您可以在下方校驗 GPG 金鑰的詳細資料。

  • 校驗 CHECKSUM 檔案是否有效

    for checksum in *-CHECKSUM; do gpgv --keyring ./fedora.gpg "$checksum"; done
  • 驗證校驗碼是否匹配

    sha256sum --ignore-missing -c *-CHECKSUM

如果輸出表示檔案有效,那麼就準備好可以使用了!

Package signing keys

Learn how Fedora uses package signing to help protect you.

Each stable RPM package published by the Fedora Project is signed with a GPG signature. By default, dnf and the graphical update tools will verify these signatures and refuse to install any packages that are not signed or have bad signatures. You should always verify the signature of a package before you install it. These signatures ensure that the packages you install are what was produced by the Fedora Project and have not been altered (accidentally or maliciously) by any mirror or website that is providing the packages.

目前的 GPG 金鑰

Fedora Rawhide

id:rsa4096/31645531 2024-08-10
Fingerprint:
C6E7F081CF80E13146676E88829B606631645531C6E7 F081 CF80 E131 4667 6E88 829B 6066 3164 5531
DNS OpenPGPKey:72dec291ea5c80f07dca832be132f5c6cb6d43713ec4843dff82d7ee._openpgpkey.fedoraproject.org

Fedora 42

id:rsa4096/105EF944 2024-02-12
Fingerprint:
B0F4950458F69E1150C6C5EDC8AC4916105EF944B0F4 9504 58F6 9E11 50C6 C5ED C8AC 4916 105E F944
DNS OpenPGPKey:a75bfc75bf3569a0280bd78d98a07de7ef3d7579b9dc3cfb270542c6._openpgpkey.fedoraproject.org

Fedora 41

id:rsa4096/E99D6AD1 2023-08-08
Fingerprint:
466CF2D8B60BC3057AA9453ED0622462E99D6AD1466C F2D8 B60B C305 7AA9 453E D062 2462 E99D 6AD1
DNS OpenPGPKey:4708da3c8d2e316f3321396cfb18e064f90a361490165d2723a63730._openpgpkey.fedoraproject.org

Fedora 40

id:rsa4096/A15B79CC 2023-01-24
Fingerprint:
115DF9AEF857853EE8445D0A0727707EA15B79CC115D F9AE F857 853E E844 5D0A 0727 707E A15B 79CC
DNS OpenPGPKey:4d0cd6e4349d5979387749daf5995f20d0de7f7b2fdfdc76d7eb21a1._openpgpkey.fedoraproject.org

EPEL 10

id:rsa4096/E37ED158 2023-12-12
Fingerprint:
7D8D15CBFC4E62688591FB2633D98517E37ED1587D8D 15CB FC4E 6268 8591 FB26 33D9 8517 E37E D158
DNS OpenPGPKey:1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

EPEL 9

id:rsa4096/3228467C 2021-09-07
Fingerprint:
FF8AD1344597106ECE813B918A3872BF3228467CFF8A D134 4597 106E CE81 3B91 8A38 72BF 3228 467C
DNS OpenPGPKey:1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

EPEL 8

id:rsa4096/2F86D6A1 2019-06-05
Fingerprint:
94E279EB8D8F25B21810ADF121EA45AB2F86D6A194E2 79EB 8D8F 25B2 1810 ADF1 21EA 45AB 2F86 D6A1
DNS OpenPGPKey:1a355c3f6ac5389917041321fdddee2c0ffc4a38f78adec159a015ec._openpgpkey.fedoraproject.org

棄用的 GPG 金鑰

Found a security bug?

Please take a moment and let us know. Learn how on our wiki page.