Save 35% on the LionVPN annual planGet the Deal
Learn Center

Verify VPN Downloads: Checksums, Signatures and Trust

Check a downloaded file against its release manifest, verify a detached signature, and understand the difference between integrity, signing identity and repository trust.

Use the files and verification instructions supplied for the exact release you downloaded. This guide does not certify a publisher, approve a release candidate for production, or establish repository trust.

Match the file before checking the hash

Start from Download. Match the release, operating system, architecture and package format. Keep the package and its verification files together; a checksum from a different release cannot validate your file.

  • Read whether the release is a candidate or stable release.
  • Compare the complete filename, not just the product name.
  • A completed download is separate from a successful installation or VPN connection.

A checksum detects a file mismatch

Compute SHA256 locally and compare every hexadecimal character with the entry for that filename. A mismatch is a reason to stop. A match establishes agreement with that manifest; a checksum fetched with a compromised package does not by itself authenticate its publisher.

# macOS: replace downloaded-package with the actual local filename
shasum -a 256 downloaded-package

# Windows PowerShell: use the actual local path
Get-FileHash -Algorithm SHA256 -LiteralPath .\downloaded-package

Verify the signature using the stated format

For an Ed25519 release manifest that supplies a raw 32-byte public key and signature as base64 text, the offline Node.js example below verifies the manifest bytes. Use this example only when those formats match the release instructions. Establish the expected public key through a trusted channel before relying on the result.

const fs = require('node:fs');
const crypto = require('node:crypto');
const raw = Buffer.from(fs.readFileSync('release-public-key.txt', 'utf8').trim(), 'base64');
if (raw.length !== 32) throw new Error('Unexpected public key format');
const key = crypto.createPublicKey({ key: Buffer.concat([Buffer.from('302a300506032b6570032100', 'hex'), raw]), format: 'der', type: 'spki' });
const signature = Buffer.from(fs.readFileSync('SHA256SUMS.sig', 'utf8').trim(), 'base64');
if (!crypto.verify(null, fs.readFileSync('SHA256SUMS'), key, signature)) throw new Error('Signature verification failed');
console.log('Manifest signature verified against the supplied public key');

Keep three trust questions separate

File integrity, signer identity and package-manager trust are separate checks. A valid detached release-manifest signature does not establish an APT, YUM or OpenWrt repository signature, nor an operating-system publisher identity.

  • Recompute package hashes after verifying the manifest.
  • Do not infer an EXE, DMG or app-store signing identity from a Linux manifest.
  • Do not disable package-manager signature checks to work around a failed verification.

Stop safely and share a minimal report

When a hash or signature fails, do not install the file. Record the public download URL, release filename, local computed hash and error category. Recheck the official release instructions or contact Support. Remove local usernames and private directory paths from screenshots and terminal output before sharing them.

References

Verify VPN Downloads: Checksums, Signatures and Trust | LionVPN