On Linux systems that use RPM packages, you can separately check whether an RPM file has a trusted signature and whether installed files have been changed from their original package state.
The signature and digest of the RPM file itself can be checked with rpm -K. For installed files, you can use rpm -V to compare the current files with information recorded in the RPM database, such as size, digest, permissions, and ownership.
In this article, we use the tree package on an RHEL-compatible Linux system as the verification target. We will check its signature, inspect the files owned by the package, identify a package from a file, determine whether an unknown file is managed by RPM, detect modifications, and restore the original state by reinstalling the package.
The steps that intentionally modify files are intended only for a test environment. Do not perform the modification steps in a production environment; use only rpm -V to check the files there.
Step 1: Install a Package for Verification
Section titled “Step 1: Install a Package for Verification”Install the tree package as the verification target.
sudo dnf install -y treetree will be used in the following steps to check owned files and detect modifications.
Step 2: Obtain an RPM File for Signature Verification
Section titled “Step 2: Obtain an RPM File for Signature Verification”Prepare a directory in which to store the RPM file.
sudo rm -rf /var/tmp/rpm-verification-example && sudo mkdir -p /var/tmp/rpm-verification-exampleDownload the same tree package that is already installed as an RPM file without performing an installation.
sudo dnf reinstall -y --downloadonly --downloaddir=/var/tmp/rpm-verification-example treeThe downloaded RPM file will be used to verify the signature of the package file itself.
Step 3: Verify the RPM Package Signature
Section titled “Step 3: Verify the RPM Package Signature”Use rpm -K to verify the digest and signature contained in the RPM file.
sudo rpm -K /var/tmp/rpm-verification-example/tree-*.rpmIf verification succeeds, OK is displayed in the result. For signature verification, the public key corresponding to the signature must be available as trusted RPM key information.
rpm -K checks the RPM package file itself. Its purpose is different from checking whether individual files that have already been installed have been modified.
Step 4: Check the Files Owned by a Package
Section titled “Step 4: Check the Files Owned by a Package”Use rpm -ql to list the files included in an installed package.
sudo rpm -ql treeThe list includes files managed by the tree package, such as /usr/bin/tree.
During troubleshooting, this can be used as a preliminary step before determining which package installed an application executable or configuration file.
Step 5: Identify the Owning Package from a File
Section titled “Step 5: Identify the Owning Package from a File”Use rpm -qf to identify the installed RPM package that owns a known file.
sudo rpm -qf /usr/bin/treeIf information including the tree package name, version, release, and architecture is displayed, you can confirm that /usr/bin/tree is managed by RPM.
This method is useful when you need to determine which package installed an executable file or library under investigation.
Step 6: Identify a File Not Managed by RPM
Section titled “Step 6: Identify a File Not Managed by RPM”Create a sample file to verify a file that is not owned by RPM.
printf '%s\n' 'example unowned file' | sudo tee /var/tmp/rpm-verification-example/unowned.txt >/dev/nullUse rpm -qf to search for an owning package and confirm that no corresponding installed RPM exists.
if sudo rpm -qf /var/tmp/rpm-verification-example/unowned.txt >/dev/null 2>&1; then echo "unexpected: file is owned by an installed RPM package" exit 1else echo "not owned by an installed RPM package"fiIf not owned by an installed RPM package is displayed, the file is not owned by any installed RPM package.
However, “not managed by RPM” does not mean the same thing as “malicious file.” Legitimate files created by administrators or applications can also exist outside RPM management, so you need to investigate the path, contents, creation history, related processes, and other relevant information.
Step 7: Verify the Package State Before Modification
Section titled “Step 7: Verify the Package State Before Modification”Use rpm -V to verify the files managed by the tree package.
sudo rpm -V treeIn a normal state, there is usually no output indicating differences.
rpm -V compares the current file attributes with the information stored in the RPM database. If differences are found, the affected file and symbols indicating the differing attributes are displayed.
Step 8: Detect Modification of a Package-Managed File
Section titled “Step 8: Detect Modification of a Package-Managed File”The following operations intentionally modify a file for verification purposes. Run them only in a disposable test environment.
Append sample data to the end of /usr/bin/tree to change it from the state in which it was installed by the package.
sudo sh -c 'printf "\nRPM verification example\n" >> /usr/bin/tree'Run rpm -V again.
sudo rpm -V treeWhen the modification is detected, a line containing /usr/bin/tree is displayed.
The displayed symbols indicate which attributes no longer match the information in the RPM database. Because this example adds content to the file, differences in size, digest, modification time, and other attributes can be detected.
The output of rpm -V provides evidence that a modification exists. This result alone cannot determine whether the change is a legitimate operational change, a malfunction, or an unauthorized modification.
Step 9: Reinstall the Package and Restore It
Section titled “Step 9: Reinstall the Package and Restore It”Reinstall tree to restore the file modified for verification to the original package contents.
sudo dnf reinstall -y treeAfter reinstalling the package, verify it again.
sudo rpm -V treeIf the intentionally created difference has been resolved, there will no longer be output indicating a modification to /usr/bin/tree.
If you find differences in a real environment, do not automatically reinstall the package without investigating the cause. First determine whether the file was intentionally modified as part of a configuration change, updated by an application, or potentially altered without authorization, and then decide on the appropriate recovery method.
Step 10: Remove the Verification Files
Section titled “Step 10: Remove the Verification Files”Finally, remove the working directory that contains the RPM used for signature verification and the file not managed by RPM.
sudo rm -rf /var/tmp/rpm-verification-exampleSummary
Section titled “Summary”With RPM, use different commands depending on the purpose of the investigation.
rpm -K: Check the signature and digest of an RPM package filerpm -ql: List the files owned by an installed packagerpm -qf: Identify the installed package that owns a filerpm -V: Compare installed files with information stored in the RPM database
By combining these commands, you can progressively verify file origins, identify files outside RPM management, and detect modifications to package-managed files.