Skip to content

Verify RPM Package Signatures, Owned Files, and Modifications

On Linux systems that use RPM packages, you can separately check whether an RPM file has a trusted signature and whether installed files have been changed from their original package state.

The signature and digest of the RPM file itself can be checked with rpm -K. For installed files, you can use rpm -V to compare the current files with information recorded in the RPM database, such as size, digest, permissions, and ownership.

In this article, we use the tree package on an RHEL-compatible Linux system as the verification target. We will check its signature, inspect the files owned by the package, identify a package from a file, determine whether an unknown file is managed by RPM, detect modifications, and restore the original state by reinstalling the package.

The steps that intentionally modify files are intended only for a test environment. Do not perform the modification steps in a production environment; use only rpm -V to check the files there.

Step 1: Install a Package for Verification

Section titled “Step 1: Install a Package for Verification”

Install the tree package as the verification target.

Terminal window
sudo dnf install -y tree

tree will be used in the following steps to check owned files and detect modifications.

Step 2: Obtain an RPM File for Signature Verification

Section titled “Step 2: Obtain an RPM File for Signature Verification”

Prepare a directory in which to store the RPM file.

Terminal window
sudo rm -rf /var/tmp/rpm-verification-example && sudo mkdir -p /var/tmp/rpm-verification-example

Download the same tree package that is already installed as an RPM file without performing an installation.

Terminal window
sudo dnf reinstall -y --downloadonly --downloaddir=/var/tmp/rpm-verification-example tree

The downloaded RPM file will be used to verify the signature of the package file itself.

Use rpm -K to verify the digest and signature contained in the RPM file.

Terminal window
sudo rpm -K /var/tmp/rpm-verification-example/tree-*.rpm

If verification succeeds, OK is displayed in the result. For signature verification, the public key corresponding to the signature must be available as trusted RPM key information.

rpm -K checks the RPM package file itself. Its purpose is different from checking whether individual files that have already been installed have been modified.

Step 4: Check the Files Owned by a Package

Section titled “Step 4: Check the Files Owned by a Package”

Use rpm -ql to list the files included in an installed package.

Terminal window
sudo rpm -ql tree

The list includes files managed by the tree package, such as /usr/bin/tree.

During troubleshooting, this can be used as a preliminary step before determining which package installed an application executable or configuration file.

Step 5: Identify the Owning Package from a File

Section titled “Step 5: Identify the Owning Package from a File”

Use rpm -qf to identify the installed RPM package that owns a known file.

Terminal window
sudo rpm -qf /usr/bin/tree

If information including the tree package name, version, release, and architecture is displayed, you can confirm that /usr/bin/tree is managed by RPM.

This method is useful when you need to determine which package installed an executable file or library under investigation.

Step 6: Identify a File Not Managed by RPM

Section titled “Step 6: Identify a File Not Managed by RPM”

Create a sample file to verify a file that is not owned by RPM.

Terminal window
printf '%s\n' 'example unowned file' | sudo tee /var/tmp/rpm-verification-example/unowned.txt >/dev/null

Use rpm -qf to search for an owning package and confirm that no corresponding installed RPM exists.

Terminal window
if sudo rpm -qf /var/tmp/rpm-verification-example/unowned.txt >/dev/null 2>&1; then
echo "unexpected: file is owned by an installed RPM package"
exit 1
else
echo "not owned by an installed RPM package"
fi

If not owned by an installed RPM package is displayed, the file is not owned by any installed RPM package.

However, “not managed by RPM” does not mean the same thing as “malicious file.” Legitimate files created by administrators or applications can also exist outside RPM management, so you need to investigate the path, contents, creation history, related processes, and other relevant information.

Step 7: Verify the Package State Before Modification

Section titled “Step 7: Verify the Package State Before Modification”

Use rpm -V to verify the files managed by the tree package.

Terminal window
sudo rpm -V tree

In a normal state, there is usually no output indicating differences.

rpm -V compares the current file attributes with the information stored in the RPM database. If differences are found, the affected file and symbols indicating the differing attributes are displayed.

Step 8: Detect Modification of a Package-Managed File

Section titled “Step 8: Detect Modification of a Package-Managed File”

The following operations intentionally modify a file for verification purposes. Run them only in a disposable test environment.

Append sample data to the end of /usr/bin/tree to change it from the state in which it was installed by the package.

Terminal window
sudo sh -c 'printf "\nRPM verification example\n" >> /usr/bin/tree'

Run rpm -V again.

Terminal window
sudo rpm -V tree

When the modification is detected, a line containing /usr/bin/tree is displayed.

The displayed symbols indicate which attributes no longer match the information in the RPM database. Because this example adds content to the file, differences in size, digest, modification time, and other attributes can be detected.

The output of rpm -V provides evidence that a modification exists. This result alone cannot determine whether the change is a legitimate operational change, a malfunction, or an unauthorized modification.

Step 9: Reinstall the Package and Restore It

Section titled “Step 9: Reinstall the Package and Restore It”

Reinstall tree to restore the file modified for verification to the original package contents.

Terminal window
sudo dnf reinstall -y tree

After reinstalling the package, verify it again.

Terminal window
sudo rpm -V tree

If the intentionally created difference has been resolved, there will no longer be output indicating a modification to /usr/bin/tree.

If you find differences in a real environment, do not automatically reinstall the package without investigating the cause. First determine whether the file was intentionally modified as part of a configuration change, updated by an application, or potentially altered without authorization, and then decide on the appropriate recovery method.

Finally, remove the working directory that contains the RPM used for signature verification and the file not managed by RPM.

Terminal window
sudo rm -rf /var/tmp/rpm-verification-example

With RPM, use different commands depending on the purpose of the investigation.

  • rpm -K: Check the signature and digest of an RPM package file
  • rpm -ql: List the files owned by an installed package
  • rpm -qf: Identify the installed package that owns a file
  • rpm -V: Compare installed files with information stored in the RPM database

By combining these commands, you can progressively verify file origins, identify files outside RPM management, and detect modifications to package-managed files.

Category: Linux