Verify a download
How to check that an installer is the one that was released, before you run it.
Why
The installer is not yet signed with a publisher certificate, so Windows cannot tell you who made it. You can find out yourself, in two ways. The first takes ten seconds and is enough for most people. The second proves more.
Check the SHA-256
The downloads page shows the SHA-256 of every installer. Compare it with the file you have.
In PowerShell, in the folder you downloaded to:
Get-FileHash .\PluggedDesk-Setup-0.4.0-win-x64.exe -Algorithm SHA256
The Hash it prints must be the same as the one on the downloads page, character for character. Capital and small
letters do not matter. If it differs, do not run the file, and tell us.
This proves that the file is the one this site lists. It relies on this site.
Check the signature
Every release has a manifest, pluggeddesk-update.json, and a signature of it, pluggeddesk-update.json.sig. The
manifest names the installer, its size and its SHA-256. The signature is made with the PluggedDesk release key, which is
not kept on this site. Checking it proves that the release came from the holder of that key, wherever you got the files.
Download both files from the downloads page (Signed manifest and Signature), then:
- Read the manifest. It is plain JSON.
installer.sha256must be the SHA-256 of your installer, andinstaller.sizeits size in bytes. - Verify the signature. The
.sigfile is JSON with three values:alg(alwaysES256),kid(the key's name) andsig(the signature, in base64). The signature is ECDSA with P-256 and SHA-256 over the exact bytes of the manifest, written as the two numbers r and s, 32 bytes each.
The public half of the release key, as SubjectPublicKeyInfo in base64:
| Key | Public key |
|---|---|
pluggeddesk-release-2026-09 |
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEAl8QcnC7mgNKtZk66R188Vv7Z9wOHkEPeUtblQYBUFUxo7UWi5dhANPGIQ5S/uccdT7oQqnE0No0GjDVzpm6DA== |
In PowerShell 7:
$key = [Security.Cryptography.ECDsa]::Create()
$spki = [Convert]::FromBase64String('MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEAl8QcnC7mgNKtZk66R188Vv7Z9wOHkEPeUtblQYBUFUxo7UWi5dhANPGIQ5S/uccdT7oQqnE0No0GjDVzpm6DA==')
$read = 0
$key.ImportSubjectPublicKeyInfo($spki, [ref]$read)
$manifest = [IO.File]::ReadAllBytes("$PWD\pluggeddesk-update.json")
$signature = [Convert]::FromBase64String((Get-Content .\pluggeddesk-update.json.sig | ConvertFrom-Json).sig)
$key.VerifyData($manifest, $signature, 'SHA256')
It must print True.
The same public key is compiled into PluggedDesk. That is how the application checks an update by itself: see Updates.
What this does not prove
A checksum and a signature say that a file is the one that was released. They say nothing about whether the release is free of faults. For what each release is known not to do yet, read its entry in the changelog.