Can Unrar Check RAR Digital Signatures?
This article examines whether the command-line utility
unrar can verify digital signatures on archives prior to
extraction. While legacy versions of RAR software included a proprietary
authenticity verification feature, modern versions of unrar
do not support digital signature checks. Users seeking to verify the
authenticity and integrity of an archive must rely on modern external
cryptographic tools before running the extraction command.
The Short Answer
No, modern versions of unrar cannot check the digital
signature of an archive before extracting it. The command-line
unrar utility lacks built-in functionality to parse,
validate, or enforce digital signatures or public-key certificates on
modern archives.
The Removal of Authenticity Verification (AV)
Older RAR formats (RAR 2.x and 3.x) featured a proprietary system
called Authenticity Verification (AV). This feature allowed archive
creators to embed a proprietary signature containing the creator's name,
archive name, and timestamp. Legacy versions of the software included an
option (-av) to check or enforce these signatures.
However, starting with WinRAR and unrar version 5.0,
RARLAB discontinued the Authenticity Verification feature
completely:
- Weak Cryptography: The legacy AV system relied on outdated cryptographic methods that did not meet modern security standards.
- Format Transition: The introduction of the RAR5 format overhauled the entire archive structure, omitting the proprietary AV feature entirely.
- Obsolete Switches: Modern command-line builds of
unrarignore or reject legacy AV verification commands.
Integrity Checks vs. Digital Signatures
Modern unrar still performs data integrity checks, but
these must not be confused with digital signatures:
- Checksums (CRC32 and BLAKE2sp): RAR archives can
contain CRC32 or BLAKE2sp hashes to verify that the extracted data is
not corrupted. You can test an archive's data integrity before unpacking
by running
unrar t archive.rar. - Lack of Identity Verification: Checksums merely confirm that the file is not corrupted; they do not verify who created the file or protect against a malicious actor who modifies both the data and the checksum.
How to Verify Archives Before Extraction
Because unrar does not handle digital authenticity,
signature verification must be decoupled from the extraction process. To
safely verify an archive before extracting:
- Use Detached Signatures: Archive distributors
typically provide a detached cryptographic signature using tools like
GnuPG (
.sigor.ascfiles), Minisign, or Signify. - Verify First: Run the verification tool against the
archive before interacting with
unrar. For example, with GnuPG:gpg --verify archive.rar.sig archive.rar - Extract Conditionally: Only execute
unrar x archive.rarif the verification step succeeds.