Navigation

Verify Integrity of MongoDB Packages

The MongoDB release team digitally signs all software packages to certify that a particular MongoDB package is a valid and unaltered MongoDB release. Before installing MongoDB, you should validate the package using either the provided PGP signature or SHA-256 checksum.

PGP signatures provide the strongest guarantees by checking both the authenticity and integrity of a file to prevent tampering.

Cryptographic checksums only validate file integrity to prevent network transmission errors.

Verify Linux/macOS Packages

Use PGP/GPG

MongoDB signs each release branch with a different PGP key. The public key files for each release branch since MongoDB 2.2 are available for download from the key server in both textual .asc and binary .pub formats.

1

Download the MongoDB installation file.

Download the binaries from MongoDB Download Center based on your environment.

For example, to download the 3.4.9 release for macOS through the shell, run this command:

curl -LO https://fastdl.mongodb.org/osx/mongodb-osx-ssl-x86_64-3.4.9.tgz
2

Download the public signature file.

curl -LO https://fastdl.mongodb.org/osx/mongodb-osx-ssl-x86_64-3.4.9.tgz.sig
3

Download then import the key file.

If you have not downloaded and imported the MongoDB 3.4 public key, run these commands:

curl -LO https://www.mongodb.org/static/pgp/server-3.4.asc
gpg --import server-3.4.asc

PGP should return this response:

gpg: key BC711F9BA15703C6: public key "MongoDB 3.4 Release Signing Key <packaging@mongodb.com>" imported
gpg: Total number processed: 1
gpg:               imported: 1
4

Verify the MongoDB installation file.

Run this command:

gpg --verify mongodb-osx-ssl-x86_64-3.4.9.tgz.sig mongodb-osx-ssl-x86_64-3.4.9.tgz

GPG should return this response:

gpg: Signature made Mon Sep 11 12:03:48 2017 EDT
gpg:                using RSA key BC711F9BA15703C6
gpg: Good signature from "MongoDB 3.4 Release Signing Key <packaging@mongodb.com>" [unknown]

If you receive a message this error message, confirm that you imported the correct public key:

gpg: Signature made Mon Sep 11 12:03:48 2017 EDT using RSA key BC711F9BA15703C6
gpg: Can't check signature: public key not found

gpg will return the following message if the package is properly signed, but you do not currently trust the signing key in your local trustdb.

gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0C49 F373 0359 A145 1858  5931 BC71 1F9B A157 03C6

Use SHA-256

1

Download the MongoDB installation file.

Download the binaries from MongoDB Download Center based on your environment.

For example, to download the 3.4.9 release for macOS through the shell, type this command:

curl -LO https://fastdl.mongodb.org/osx/mongodb-osx-ssl-x86_64-3.4.9.tgz
2

Download the SHA256 file.

curl -LO https://fastdl.mongodb.org/osx/mongodb-osx-ssl-x86_64-3.4.9.tgz.sha256
3

Use the SHA-256 checksum to verify the MongoDB package file.

Compute the checksum of the package file:

shasum -c mongodb-osx-ssl-x86_64-3.4.9.tgz.sha256

which should return the following if the checksum matched the downloaded package:

mongodb-osx-ssl-x86_64-3.4.9.tgz: OK

Verify Windows Packages

This verifies the MongoDB binary against its SHA256 key.

1

Download the MongoDB .msi installation file.

Download the .msi from the MongoDB Download Center.

For example to download the latest 4.0 of MongoDB Community Edition, from the MongoDB Download Center:

  1. In the Version dropdown, select the version that corresponds to the latest MongoDB Server 4.0.
  2. In the OS dropdown, Windows 64-bit X64 should be selected.
  3. In the Package drop down, MSI should be selected.
  4. Click Download and save the file to your Downloads folder.
2

Get the public signature file.

Get the public signature file for your MongoDB version.

For example, for the SHA256 signature for the latest 4.0 of MongoDB Community Edition,

  1. From https://downloads.mongodb.org/win32/mongodb-win32-x86_64-2008plus-ssl-4.0.6-signed.msi.sha256, copy the content.
  2. Save the content to a file mongodb-win32-x86_64-2008plus-ssl-4.0.6-signed.msi.sha256 in your Downloads folder.
3

Compare the signature file to the MongoDB installer hash.

To compare the signature file to the hash of the MongoDB binary, invoke this Powershell script:

$sigHash = (Get-Content $Env:HomePath\Downloads\mongodb-win32-x86_64-2008plus-ssl-4.0.6-signed.msi.sha256 | Out-String).SubString(0,64).ToUpper(); `
$fileHash = (Get-FileHash $Env:HomePath\Downloads\mongodb-win32-x86_64-2008plus-ssl-4.0.6-signed.msi).Hash.Trim(); `
echo $sigHash; echo $fileHash; `
$sigHash -eq $fileHash
E2AC83CFEE3350012A641405CE5BA5C3CFFE3F8D1A0CD5E0EB3E332246A9CC20
E2AC83CFEE3350012A641405CE5BA5C3CFFE3F8D1A0CD5E0EB3E332246A9CC20
True

The command outputs three lines:

  • A SHA256 hash that you downloaded directly from MongoDB.
  • A SHA256 hash computed from the MongoDB binary you downloaded from MongoDB.
  • A True or False result depending if the hashes match.

If the hashes match, the MongoDB binary is verified.