Resources

Verified disk images

Operating systems and boot tools, downloaded from their vendor, with the checksum we verified against the vendor's signature — and the command to verify it yourself.

46 files 19 verified signatures 17 published checksums checked on 2026-09-26 from 2 networks Verify a file

Personal computer

To install or try a system on a PC. Beginners: Linux Mint or Ubuntu.

Debian 13.7.0

GNOME live (try without installing)amd643.8 GB

Signature verified
SHA-256 e94859a83b30…dba87a17

SHA-256 e94859a83b305cae5125dc9c6080ced040c59d099ea7381e7f300fd1dba87a17

Checksum read from SHA256SUMS, signature SHA256SUMS.sign verified with key DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B (Debian CD signing key <debian-cd@lists.debian.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.debian.org/CD/verify

License: free software (DFSG) · File : debian-live-13.7.0-amd64-gnome.iso

Debian 13.7.0

network install (netinst)amd64793 MB

Signature verified
SHA-256 a7ef94ac2fb9…6167e355

SHA-256 a7ef94ac2fb9a7fec454552abd629b7cc9d5155c886165a45649f5ce6167e355

Checksum read from SHA256SUMS, signature SHA256SUMS.sign verified with key DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B (Debian CD signing key <debian-cd@lists.debian.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.debian.org/CD/verify

License: free software (DFSG) · File : debian-13.7.0-amd64-netinst.iso

Debian 13.7.0

network install (netinst)arm64735 MB

Signature verified
SHA-256 6e93fa1759bd…cc17024b

SHA-256 6e93fa1759bd9d4b0fc11e938987de6967ee7de5297dac1be27c3a75cc17024b

Checksum read from SHA256SUMS, signature SHA256SUMS.sign verified with key DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B (Debian CD signing key <debian-cd@lists.debian.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.debian.org/CD/verify

License: free software (DFSG) · File : debian-13.7.0-arm64-netinst.iso

Ubuntu 26.04.1

Desktop LTSamd646.5 GB

Signature verified
SHA-256 601e30fbf5d9…cf1bda1f

SHA-256 601e30fbf5d97759367c632e2c33630665039b7e2158fd068403da3ccf1bda1f

Checksum read from SHA256SUMS, signature SHA256SUMS.gpg verified with key 8439 38DF 228D 22F7 B374 2BC0 D94A A3F0 EFE2 1092 (Ubuntu CD Image Automatic Signing Key (2012) <cdimage@ubuntu.com>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: ubuntu.com/tutorials/how-to-verify-ubuntu

License: free software · File : ubuntu-26.04.1-desktop-amd64.iso

Linux Mint 22.3

Cinnamonamd643.1 GB

Signature verified
SHA-256 a081ab202cfd…7c459bd4

SHA-256 a081ab202cfda17f6924128dbd2de8b63518ac0531bcfe3f1a1b88097c459bd4

Checksum read from sha256sum.txt, signature sha256sum.txt.gpg verified with key 27DE B156 44C6 B3CF 3BD7 D291 300F 846B A25B AE09 (Linux Mint ISO Signing Key <root@linuxmint.com>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: linuxmint.com/verify.php

License: free software · File : linuxmint-22.3-cinnamon-64bit.iso

Fedora Workstation 44

livex86_642.9 GB

Signature verified
SHA-256 1620295f6a00…6a426ddf

SHA-256 1620295f6a00c27c3208f0c00b8ece4eab1ec69b9002152d97488bf26a426ddf

Checksum read from Fedora-Workstation-44-1.7-x86_64-CHECKSUM (signed file), signature verified with key 36F6 12DC F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6 (Fedora (44) <fedora-44-primary@fedoraproject.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: fedoraproject.org/security

License: free software · File : Fedora-Workstation-Live-44-1.7.x86_64.iso

openSUSE Leap 16.0

offline installerx86_644.5 GB

Signature verified
SHA-512 94411793a187…a8469971

SHA-512 94411793a1878b3558211c8bbe4f3823c3c5212cc2dd9f9e4532a18be7eddd3be14db5a3bb47a2f36dd957e190ea706cd45af16bce218dfc00f71e64a8469971

Checksum read from Leap-16.0-offline-installer-x86_64.install.iso.sha512, signature Leap-16.0-offline-installer-x86_64.install.iso.sha512.asc verified with key AD48 5664 E901 B867 051A B15F 35A2 F86E 29B7 00A4 (openSUSE Project Signing Key <opensuse@opensuse.org> (Leap 16)), on 2026-09-26, from 2 separate networks.

Key published by the vendor: download.opensuse.org/distribution/leap/16.0/repo/oss/repodata/repomd.xml.key (key published in the official Leap 16.0 repository) and en.opensuse.org/openSUSE:Download_help

License: free software · File : Leap-16.0-offline-installer-x86_64.install.iso

Arch Linux 2026.09.01

installation imagex86_641.6 GB

Checksum published
SHA-256 be8458032f81…65561c91

SHA-256 be8458032f8105e60ee2a3067f950b6e3c007ee51b38dac50e8b48e765561c91

Checksum published by the vendor in json, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): archlinux-2026.09.01-x86_64.iso.sig.

License: free software · File : archlinux-2026.09.01-x86_64.iso

Privacy and security

Tails leaves no trace; Qubes compartmentalizes; Kali is for penetration testing.

Kali Linux 2026.2

installeramd644.8 GB

Signature verified
SHA-256 6dbefacc95e3…6c3d2ba3

SHA-256 6dbefacc95e3b556c19c48e8bae39b8b505e2d3a1aba0bfb7ab62b036c3d2ba3

Checksum read from SHA256SUMS, signature SHA256SUMS.gpg verified with key 827C 8569 F251 8CC6 77FE CA1A ED65 462E C8D5 E4C5 (Kali Linux Archive Automatic Signing Key (2025) <devel@kali.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.kali.org/docs/introduction/download-official-kali-linux-images/

License: free software · File : kali-linux-2026.2-installer-amd64.iso

Kali Linux 2026.2

liveamd64

Signature verified
SHA-256 49e90e694d1b…769c773a

SHA-256 49e90e694d1b3dedd47f94afbe99dfdd5afb41c8462b638bbd332929769c773a

Checksum read from SHA256SUMS, signature SHA256SUMS.gpg verified with key 827C 8569 F251 8CC6 77FE CA1A ED65 462E C8D5 E4C5 (Kali Linux Archive Automatic Signing Key (2025) <devel@kali.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.kali.org/docs/introduction/download-official-kali-linux-images/

License: free software · File : kali-linux-2026.2-live-amd64.iso

Tails 7.13

USB imageamd641.9 GB

Checksum published
SHA-256 8c4e63c7c47a…1621f468

SHA-256 8c4e63c7c47a000335bf2e66158c0d062c063619599e45d717759d8f1621f468

Checksum published by the vendor in latest.json, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): tails-amd64-7.13.img.sig.

License: free software · File : tails-amd64-7.13.img

Tails 7.13

ISO image (DVD, virtual machines)amd641.9 GB

Checksum published
SHA-256 cacb025f452a…b6336682

SHA-256 cacb025f452ad010257dd5d3ba7bf7cb1bdfde50e8e583670d604d0bb6336682

Checksum published by the vendor in latest.json, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): tails-amd64-7.13.iso.sig.

License: free software · File : tails-amd64-7.13.iso

Qubes OS 4.3.1

installerx86_648.4 GB

Signature verified
SHA-256 6ab99dee2c7a…24527db6

SHA-256 6ab99dee2c7a7b2c32053d3531084aaf3af703815842b67f90a87ba324527db6

Checksum read from Qubes-R4.3.1-x86_64.iso.DIGESTS, signature Qubes-R4.3.1-x86_64.iso.DIGESTS.asc verified with key F3FA 3F99 D628 1F7B 3A3E 5E87 1C3D 9B62 7F3F ADA4 (Qubes OS Release 4.3 Signing Key), on 2026-09-26, from 2 separate networks.

Key published by the vendor: www.qubes-os.org/security/verifying-signatures/ (release key, signed by the master key 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494)

The file itself carries a vendor signature (OpenPGP): Qubes-R4.3.1-x86_64.iso.asc.

License: free software · File : Qubes-R4.3.1-x86_64.iso

Servers and virtualization

Headless systems, hypervisors and storage.

Ubuntu Server 26.04.1

LTSamd642.9 GB

Signature verified
SHA-256 cc8a95cde20f…17f1d927

SHA-256 cc8a95cde20f6ced61a322420de00f10cc3c90ced545daa46cb9c1a117f1d927

Checksum read from SHA256SUMS, signature SHA256SUMS.gpg verified with key 8439 38DF 228D 22F7 B374 2BC0 D94A A3F0 EFE2 1092 (Ubuntu CD Image Automatic Signing Key (2012) <cdimage@ubuntu.com>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: ubuntu.com/tutorials/how-to-verify-ubuntu

License: free software · File : ubuntu-26.04.1-live-server-amd64.iso

Fedora Server 44

network install (netinst)x86_641.2 GB

Signature verified
SHA-256 ae20c06bea74…74b70283

SHA-256 ae20c06bea746913cadea7d80463e13f4bf55bee4df2918111c921c674b70283

Checksum read from Fedora-Server-44-1.7-x86_64-CHECKSUM (signed file), signature verified with key 36F6 12DC F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6 (Fedora (44) <fedora-44-primary@fedoraproject.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: fedoraproject.org/security

License: free software · File : Fedora-Server-netinst-x86_64-44-1.7.iso

Alpine Linux 3.24.2

standardx86_64370 MB

Checksum published
SHA-256 20c026e3a788…63d63296

SHA-256 20c026e3a788bfb75fc8b50a54bcc12aee85e3c75909740bba6a6f4563d63296

Checksum published by the vendor in latest-releases.yaml, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): alpine-standard-3.24.2-x86_64.iso.asc.

License: free software · File : alpine-standard-3.24.2-x86_64.iso

Alpine Linux 3.24.2

virt (virtual machines)x86_6469 MB

Checksum published
SHA-256 3ab424762af7…22e7130b

SHA-256 3ab424762af704b2c2a9e57df1dc37f982af260071504d977f2fb96822e7130b

Checksum published by the vendor in latest-releases.yaml, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): alpine-virt-3.24.2-x86_64.iso.asc.

License: free software · File : alpine-virt-3.24.2-x86_64.iso

Rocky Linux 10

full DVDx86_6410 GB

Signature verified
SHA-256 16ca9c96cdb2…f91c8feb

SHA-256 16ca9c96cdb221ba6e1f68579f21bd69fd8da81c6a921d9068949796f91c8feb

Checksum read from Rocky-10-latest-x86_64-dvd.iso.CHECKSUM, signature Rocky-10-latest-x86_64-dvd.iso.CHECKSUM.asc verified with key FC22 6859 C086 0BF0 DDB9 5B08 5B10 6C73 6FED FC85 (Release Engineering (Rocky Linux 10) <releng@rockylinux.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: rockylinux.org/keys

License: free software · File : Rocky-10-latest-x86_64-dvd.iso

Rocky Linux 10

minimalx86_642.1 GB

Signature verified
SHA-256 aac6ac3ce781…7302f6c8

SHA-256 aac6ac3ce781b91a91ce78463405f66c611a5dca4b3840c79e5e01d97302f6c8

Checksum read from Rocky-10-latest-x86_64-minimal.iso.CHECKSUM, signature Rocky-10-latest-x86_64-minimal.iso.CHECKSUM.asc verified with key FC22 6859 C086 0BF0 DDB9 5B08 5B10 6C73 6FED FC85 (Release Engineering (Rocky Linux 10) <releng@rockylinux.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: rockylinux.org/keys

License: free software · File : Rocky-10-latest-x86_64-minimal.iso

AlmaLinux 10.2

minimalx86_641.7 GB

Signature verified
SHA-256 1b532f534231…6eed41a4

SHA-256 1b532f534231da0d1cd0ccae622bea6cd588d8a0d7b259f1f131501a6eed41a4

Checksum read from CHECKSUM (signed file), signature verified with key EE6D B7B9 8F5B F5ED D9DA 0DE5 DEE5 C11C C2A1 E572 (AlmaLinux OS 10 <packager@almalinux.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: almalinux.org/security/

License: free software · File : AlmaLinux-10.2-x86_64-minimal.iso

Proxmox Backup Server 4.2-1

backupamd641.5 GB

Checksum published
SHA-256 2fb299deac39…a1d5453e

SHA-256 2fb299deac3929253712c9c3dfc9237edbe70af83c8848467616b771a1d5453e

Checksum published by the vendor in proxmox-backup-server_4.2-1.iso.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): proxmox-backup-server_4.2-1.iso.asc.

License: AGPL-3.0 · File : proxmox-backup-server_4.2-1.iso

Proxmox Mail Gateway 9.1-1

mail gatewayamd641.7 GB

Checksum published
SHA-256 79402f6398c5…c6c864d6

SHA-256 79402f6398c50a76fca66a32c3c0a50da3f71d35c1d7a1bea022e4b1c6c864d6

Checksum published by the vendor in proxmox-mail-gateway_9.1-1.iso.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): proxmox-mail-gateway_9.1-1.iso.asc.

License: AGPL-3.0 · File : proxmox-mail-gateway_9.1-1.iso

Proxmox VE 9.2-1

virtualizationamd641.7 GB

Checksum published
SHA-256 4e88fe416df9…73ef2c6c

SHA-256 4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c

Checksum published by the vendor in proxmox-ve_9.2-1.iso.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): proxmox-ve_9.2-1.iso.asc.

License: AGPL-3.0 · File : proxmox-ve_9.2-1.iso

TrueNAS Community Edition 25.10.7

storage (NAS)amd642.3 GB

Checksum published
SHA-256 54ce9441ce66…7a007c8e

SHA-256 54ce9441ce66966a392e28f63604ca3c2c083d0bec4db7bb5af2f74f7a007c8e

Checksum published by the vendor in TrueNAS-SCALE-25.10.7.iso.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: open source (image built by iXsystems) · File : TrueNAS-SCALE-25.10.7.iso

Firewall and network

Routers and firewalls to install on a dedicated machine.

OPNsense 26.1.6

dvd (ISO installer, bz2-compressed)amd64542 MB

Signature verified
SHA-256 6ba3633d9c0f…90a4f08c

SHA-256 6ba3633d9c0f96d82c792015a45f4b8aac45ea8fa2bdba3c5e534d0c90a4f08c

Checksum read from OPNsense-26.1.6-checksums-amd64.sha256, signature OPNsense-26.1.6-checksums-amd64.sha256.sig verified (OpenSSL) with key D882 8C06 58FF B5E9 00A3 1269 D709 1B40 2497 D570 6B9B E179 E01E D8C8 8A0D 49D8 (OPNsense 26.1 (clé RSA 4096, fichier OPNsense-26.1.pub)), on 2026-09-26, from 2 separate networks.

Key published by the vendor: docs.opnsense.org/manual/install.html (the key is published on the official mirrors listed by opnsense.org/download; fingerprint read on 2026-09-26 from mirror.dns-root.de)

The file itself carries a vendor signature (OpenSSL, uncompressed image): OPNsense-26.1.6-dvd-amd64.iso.sig.

License: BSD-2 · File : OPNsense-26.1.6-dvd-amd64.iso.bz2

OPNsense 26.1.6

vga (USB drive, bz2-compressed)amd64559 MB

Signature verified
SHA-256 cf8deca3033b…9a551f4a

SHA-256 cf8deca3033b66138930d417c879cb93b7930d1ca8dabd7e1aea914f9a551f4a

Checksum read from OPNsense-26.1.6-checksums-amd64.sha256, signature OPNsense-26.1.6-checksums-amd64.sha256.sig verified (OpenSSL) with key D882 8C06 58FF B5E9 00A3 1269 D709 1B40 2497 D570 6B9B E179 E01E D8C8 8A0D 49D8 (OPNsense 26.1 (clé RSA 4096, fichier OPNsense-26.1.pub)), on 2026-09-26, from 2 separate networks.

Key published by the vendor: docs.opnsense.org/manual/install.html (the key is published on the official mirrors listed by opnsense.org/download; fingerprint read on 2026-09-26 from mirror.dns-root.de)

The file itself carries a vendor signature (OpenSSL, uncompressed image): OPNsense-26.1.6-vga-amd64.img.sig.

License: BSD-2 · File : OPNsense-26.1.6-vga-amd64.img.bz2

pfSense CE

installeramd64

At the vendor

Since 2024, Netgate requires an account to download the image; the SHA-256 checksum is shown after signing in.

BSD

Another family of free operating systems.

FreeBSD 15.1

disc1 (installation)amd641.4 GB

Checksum published
SHA-256 fa27646f05a1…e1aa5fd9

SHA-256 fa27646f05a1440fd26ffbb85e06a50bc86e128242a4e9cb7bb3ea76e1aa5fd9

Checksum published by the vendor in CHECKSUM.SHA256-FreeBSD-15.1-RELEASE-amd64, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: BSD · File : FreeBSD-15.1-RELEASE-amd64-disc1.iso

The project signs its checksums in the release announcement (PGP e-mail), not in a file next to the images.

FreeBSD 15.1

memstick (USB drive)amd641.6 GB

Checksum published
SHA-256 26c6d5de1156…c5239eae

SHA-256 26c6d5de1156e7a99df920d047578b504c4899865d91b1156b1de1a0c5239eae

Checksum published by the vendor in CHECKSUM.SHA256-FreeBSD-15.1-RELEASE-amd64, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: BSD · File : FreeBSD-15.1-RELEASE-amd64-memstick.img

The project signs its checksums in the release announcement (PGP e-mail), not in a file next to the images.

Raspberry Pi boards

SD card images, to write with Raspberry Pi Imager.

Raspberry Pi OS 2026-09-15

with desktoparm641.4 GB

Checksum published
SHA-256 61d95799550a…88b799dd

SHA-256 61d95799550aac32788bb3cacc3d471dcc860f8053ce989dec4aecc388b799dd

Checksum published by the vendor in 2026-09-15-raspios-trixie-arm64.img.xz.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): 2026-09-15-raspios-trixie-arm64.img.xz.sig.

License: free software + proprietary firmware · File : 2026-09-15-raspios-trixie-arm64.img.xz

Raspberry Pi OS Lite 2026-09-15

without desktoparm64541 MB

Checksum published
SHA-256 cdf4f3bfac35…aee627e5

SHA-256 cdf4f3bfac35ae947b46e4e767f935453810549779ac3290e05a6754aee627e5

Checksum published by the vendor in 2026-09-15-raspios-trixie-arm64-lite.img.xz.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): 2026-09-15-raspios-trixie-arm64-lite.img.xz.sig.

License: free software + proprietary firmware · File : 2026-09-15-raspios-trixie-arm64-lite.img.xz

Rescue

Clone a disk, partition, repair, test the memory.

Clonezilla Live 3.3.3-37

disk cloning and imagingamd64505 MB

Signature verified
SHA-256 3079458d926a…6bb3414f

SHA-256 3079458d926a37d3533e5d5caeb61b6e49c2dc69e2c97e0332ef37986bb3414f

Checksum read from SHA256SUMS, signature SHA256SUMS.gpg verified with key 54C0 821A 4871 5DAF D61B FCAF 6678 57D0 4559 9AFD (DRBL Project (Diskless Remote Boot in Linux) <drbl@clonezilla.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: identity published on hkps://keyserver.ubuntu.com; signature published on free.nchc.org.tw, the project's host (NCHC); the vendor does not publish the fingerprint on its site

License: GPL · File : clonezilla-live-3.3.3-37-amd64.iso

GParted Live 1.8.1-6

partitioningamd64720 MB

Signature verified
SHA-256 5686226c04a5…788bf705

SHA-256 5686226c04a58436f2f5a58211bfde7109e806e0236ae821f1bc6559788bf705

Checksum read from CHECKSUMS.TXT, signature CHECKSUMS.TXT.gpg verified with key EB1D D5BF 6F88 820B BCF5 356C 8E94 C9CD 163E 3FB0 (Steven Shiau (In Freedom We Trust) <steven@stevenshiau.org>), on 2026-09-26, from 2 separate networks.

Key published by the vendor: identity published on hkps://keyserver.ubuntu.com; signature published on gparted.org; the vendor does not publish the fingerprint on its site

License: GPL · File : gparted-live-1.8.1-6-amd64.iso

SystemRescue 13.02

rescueamd641.4 GB

Checksum published
SHA-256 ad4d670b7285…5d6e7572

SHA-256 ad4d670b72859d887c7960142a9a9d36a3e50446694a035e254442f65d6e7572

Checksum published by the vendor in systemrescue-13.02-amd64.iso.sha256, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

The file itself carries a vendor signature (OpenPGP): systemrescue-13.02-amd64.iso.asc.

License: GPL · File : systemrescue-13.02-amd64.iso

Memtest86+ 8.10

memory test (ISO inside a zip)x86_64234 KB

Checksum published
SHA-256 93530005d6ac…8001be9a

SHA-256 93530005d6ac6a85aa2a49c68604a43c25794ecccf796c4f8849a73a8001be9a

Checksum published by the vendor in sha256sum.txt, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: GPL-2.0 · File : mt86plus_8.10_x86_64.iso.zip

Write a USB drive

The tools that copy an image to a USB drive or an SD card.

Ventoy 1.1.17

for Linux (tar.gz)x86_6420 MB

Checksum published
SHA-256 7fb4ed08cef6…bbc43805

SHA-256 7fb4ed08cef6a6b4d39dd19260d8c80291a78dfdf9af7d461571e23cbbc43805

Checksum published by the vendor in sha256.txt, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: GPL-3.0 · File : ventoy-1.1.17-linux.tar.gz

Ventoy 1.1.17

for Windows (zip)x86_6417 MB

Checksum published
SHA-256 d250e97a7595…659dbaeb

SHA-256 d250e97a7595fdac4f97debc630d7a8da942319274a76cb32384596b659dbaeb

Checksum published by the vendor in sha256.txt, read on 2026-09-26 from 2 separate networks. That checksum file carries no verifiable signature.

License: GPL-3.0 · File : ventoy-1.1.17-windows.zip

Rufus

write an image to a USB drive (Windows)x86_64

At the vendor

No checksum published: the executable is Authenticode-signed (Akeo Consulting); Windows checks it when opened (Properties → Digital Signatures).

balenaEtcher

write an image (Windows, macOS, Linux)multi

At the vendor

No machine-readable checksums published; signed executables (Balena).

Raspberry Pi Imager

prepare an SD card (Windows, macOS, Linux)multi

At the vendor

Windows

Microsoft distributes its own images and shows their SHA-256 checksum.

Windows 10

media creation tool / ISO — Microsoftx64

At the vendor

Windows 10 support ended on 14 October 2025; only for machines that cannot move to Windows 11.

Windows 11

disk image (ISO) — Microsoftx64

At the vendor

Microsoft shows the SHA-256 checksum of each image on its page once the edition and language are chosen (section “Verify your download”). We do not host these images.

Windows 11

disk image (ISO) for ARM processorsarm64

At the vendor

Microsoft shows the SHA-256 checksum of each image on its page once the edition and language are chosen (section “Verify your download”). We do not host these images.

Windows Server 2025

180-day evaluation — Microsoftx64

At the vendor

Microsoft shows the SHA-256 checksum of each image on its page once the edition and language are chosen (section “Verify your download”). We do not host these images.

Other vendors

Only available from the vendor, account required.

macOS

installer and bootable drive — Applearm64 / x86_64

At the vendor

macOS is not distributed as an ISO: Apple explains how to get the installer and create a bootable USB drive from a Mac.

VMware ESXi / Workstation

Broadcom portal (account required)x86_64

At the vendor

Since the Broadcom acquisition, ESXi and Workstation are downloaded from the Broadcom portal; an account is required.

Verify a file

After downloading, compute the file's SHA-256 checksum and compare it with the one shown here. A single different character means the file is not the vendor's: do not use it.

Windows — PowerShell
Get-FileHash .\fichier.iso -Algorithm SHA256
Linux — terminal
sha256sum fichier.iso
macOS — Terminal
shasum -a 256 fichier.iso

Replace the name with the downloaded file's name. The computation takes a few seconds per gigabyte.

Verify this catalogue

The list above is published in a machine-readable form and signed with an OpenPGP key whose private part never leaves our workstation.

Awoui key fingerprint : B592 864E 5B51 1C32 D558 51B7 7353 3F8A 3F08 5FE9

Verification
gpg --import awoui-fichiers.asc
gpg --verify catalogue.json.asc catalogue.json

How these files are verified

  1. The checksum is read at the vendor, from its checksum file, never copied by hand.
  2. When the vendor signs that file, the signature is verified against a key whose fingerprint is written in advance in our code, together with the vendor page that publishes it. A signature that fails removes the file from the list.
  3. The check runs from two separate networks; a disagreement between them removes the file from the list and is written to the log.
  4. The check is repeated regularly; the date shown is that of the last verification.

Does a file look wrong? Write to contact@awoui.com.