Verify 7-Zip Installer Digital Signatures
This article explains how digital signature verification works for official 7-Zip installers to ensure file integrity and authenticity. Official 7-Zip downloads are protected using standard Microsoft Authenticode digital certificates issued directly to developer Igor Pavlov, alongside cryptographic SHA-256 checksums. By evaluating these cryptographic proofs, both the Windows operating system and end users can confirm that the software has not been altered or compromised by third parties.
Authenticode Digital Signatures
Official 7-Zip installer packages (such as .exe and
.msi files) contain an embedded Microsoft Authenticode
digital signature. This signature is generated using a private key
corresponding to a code-signing certificate issued to Igor Vladimirovich
Pavlov by a recognized Certificate Authority (CA).
When an installer is downloaded and run, Windows automatically initiates the verification process:
- Hash Comparison: Windows decrypts the embedded signature using the public key contained in the certificate and generates a fresh cryptographic hash of the installer file. If the file has been altered by even a single byte, the hashes will not match, invalidating the signature.
- Trust Chain Validation: Windows verifies that the certificate chains up to a trusted root CA present in the operating system's trust store.
- Timestamp Verification: The signature includes a cryptographic timestamp, proving the executable was signed while the certificate was valid, even if the certificate later expires.
Verifying the Signature via Windows File Properties
Users can manually verify the signature before running the installer:
- Right-click the downloaded 7-Zip installer and select Properties.
- Click the Digital Signatures tab. (If this tab is missing, the file is not signed and may be illegitimate.)
- Select the signature in the list (typically listed under the name Igor Pavlov) and click Details.
- Confirm that the Digital Signature Information box explicitly states: "This digital signature is OK."
Checksum Verification via SHA-256
In addition to Authenticode signatures, the official 7-Zip distribution provides SHA-256 cryptographic hashes for each release. Users can compute the local file hash and compare it against the published hash to ensure bit-level integrity:
- Using Windows PowerShell:
Get-FileHash -Algorithm SHA256 .\7zXXXX-x64.exe - Using Command Prompt:
certutil -hashfile 7zXXXX-x64.exe SHA256
If the generated hash matches the hash listed on the official distribution page, the installer is confirmed to be authentic and uncorrupted.