# Installation / signed\_sha256\_hashes file

**URL:** <https://bisq.community/t/installation-signed-sha256-hashes-file/2209>\
**Category:** Support\
**Created:** [June 7, 2017, 12:11pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209 "2017-06-07T12:11:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![JW\_88](https://bisq.community/letter_avatar/jw_88/32/5_5575768a8748004e209b776fc1b2916d.png) [@JW\_88](https://bisq.community/u/JW_88)\
**Post date:** [June 7, 2017, 12:11pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/1 "2017-06-07T12:11:44Z")

</div>

Hi All,

Installation instructions include the possibility to verify the authenticity of the download, but requires the download of the ‘signed\_sha256\_hashes.txt’ file, which I can’t find on the Github page, the PGP file is there though.

Anyone know where to find the signed\_sha256\_hashes.txt…??

Thanks

J

---

<div class="post-metadata">

**Author:** ![alexej996](https://bisq.community/user_avatar/bisq.community/alexej996/32/491_2.png) [@alexej996](https://bisq.community/u/alexej996)\
**Post date:** [June 7, 2017, 1:55pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/2 "2017-06-07T13:55:58Z")

</div>

The PGP file is the sha256 hash file signed with a public key. It is a file you need. Just download that file and Manfred’s public key (also available for download on Github as F379A1C6.asc) and check the signature. You can import the key using command line program gpg. Type “gpg --import F379A1C6.asc” to import Manfred’s public key and type “gpg --verify \<name\_of\_signature file\>” to verify your download.

To be more sure the key is correct, the fingerprint is 1DC3 C8C4 316A 698A C494 039C F5B8 4436 F379 A1C6. You can check that with “gpg --fingerprint F379A1C6”.

---

<div class="post-metadata">

**Author:** ![JW\_88](https://bisq.community/letter_avatar/jw_88/32/5_5575768a8748004e209b776fc1b2916d.png) [@JW\_88](https://bisq.community/u/JW_88)\
**Post date:** [June 7, 2017, 2:25pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/4 "2017-06-07T14:25:14Z")

</div>

Thanks for your reply,  
**gpg --fingerprint F379A1C6** gives the finger print as you have there. I have done **gpg --import F379A1C6.asc**

but i can’t get verify to work (i’m not entirely sure of the usage) but:

**gpg --verify Bitsquare-64bit-0.4.9.9.3.deb**  
& also: **gpg --verify F379A1C6.asc Bitsquare-64bit-0.4.9.9.3.deb**

gives

**gpg: verify signatures failed: unexpected data**

any help much appreciated…!

---

<div class="post-metadata">

**Author:** ![alexej996](https://bisq.community/user_avatar/bisq.community/alexej996/32/491_2.png) [@alexej996](https://bisq.community/u/alexej996)\
**Post date:** [June 7, 2017, 2:33pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/5 "2017-06-07T14:33:43Z")

</div>

> [@JW\_88](#):
>
> gpg --verify Bitsquare-64bit-0.4.9.9.3.deb

You need to specify the signature file “gpg --verify Bitsquare-64bit-0.4.9.9.3.deb.asc”. There is a second argument for the file that is being verified, but it will assume that it is “Bitsquare-64bit-0.4.9.9.3.deb”.

---

<div class="post-metadata">

**Author:** ![JW\_88](https://bisq.community/letter_avatar/jw_88/32/5_5575768a8748004e209b776fc1b2916d.png) [@JW\_88](https://bisq.community/u/JW_88)\
**Post date:** [June 7, 2017, 2:44pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/6 "2017-06-07T14:44:44Z")

</div>

> [@alexej996](#):
>
> gpg --verify Bitsquare-64bit-0.4.9.9.3.deb.asc

That did it…!

Thanks very much!!

---

<div class="post-metadata">

**Author:** ![alexej996](https://bisq.community/user_avatar/bisq.community/alexej996/32/491_2.png) [@alexej996](https://bisq.community/u/alexej996)\
**Post date:** [June 7, 2017, 2:54pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/7 "2017-06-07T14:54:01Z")

</div>

No problem. 🙂

---

<div class="post-metadata">

**Author:** ![ManfredKarrer](https://bisq.community/user_avatar/bisq.community/manfredkarrer/32/26_2.png) [@ManfredKarrer](https://bisq.community/u/ManfredKarrer)\
**Post date:** [June 7, 2017, 7:26pm UTC](https://bisq.community/t/installation-signed-sha256-hashes-file/2209/8 "2017-06-07T19:26:13Z")

</div>


