Can Unrar Check RAR Digital Signatures?

This article examines whether the command-line utility unrar can verify digital signatures on archives prior to extraction. While legacy versions of RAR software included a proprietary authenticity verification feature, modern versions of unrar do not support digital signature checks. Users seeking to verify the authenticity and integrity of an archive must rely on modern external cryptographic tools before running the extraction command.

The Short Answer

No, modern versions of unrar cannot check the digital signature of an archive before extracting it. The command-line unrar utility lacks built-in functionality to parse, validate, or enforce digital signatures or public-key certificates on modern archives.

The Removal of Authenticity Verification (AV)

Older RAR formats (RAR 2.x and 3.x) featured a proprietary system called Authenticity Verification (AV). This feature allowed archive creators to embed a proprietary signature containing the creator's name, archive name, and timestamp. Legacy versions of the software included an option (-av) to check or enforce these signatures.

However, starting with WinRAR and unrar version 5.0, RARLAB discontinued the Authenticity Verification feature completely:

  • Weak Cryptography: The legacy AV system relied on outdated cryptographic methods that did not meet modern security standards.
  • Format Transition: The introduction of the RAR5 format overhauled the entire archive structure, omitting the proprietary AV feature entirely.
  • Obsolete Switches: Modern command-line builds of unrar ignore or reject legacy AV verification commands.

Integrity Checks vs. Digital Signatures

Modern unrar still performs data integrity checks, but these must not be confused with digital signatures:

  • Checksums (CRC32 and BLAKE2sp): RAR archives can contain CRC32 or BLAKE2sp hashes to verify that the extracted data is not corrupted. You can test an archive's data integrity before unpacking by running unrar t archive.rar.
  • Lack of Identity Verification: Checksums merely confirm that the file is not corrupted; they do not verify who created the file or protect against a malicious actor who modifies both the data and the checksum.

How to Verify Archives Before Extraction

Because unrar does not handle digital authenticity, signature verification must be decoupled from the extraction process. To safely verify an archive before extracting:

  1. Use Detached Signatures: Archive distributors typically provide a detached cryptographic signature using tools like GnuPG (.sig or .asc files), Minisign, or Signify.
  2. Verify First: Run the verification tool against the archive before interacting with unrar. For example, with GnuPG:
    gpg --verify archive.rar.sig archive.rar
  3. Extract Conditionally: Only execute unrar x archive.rar if the verification step succeeds.