How to Unrar and Verify GPG Signatures

This article explains how to extract files from a RAR archive and automatically verify their authenticity using GNU Privacy Guard (GPG). Because the unrar utility does not have built-in cryptographic verification tools, combining unrar with gpg via shell commands or automation scripts provides a seamless, secure workflow to ensure extracted contents have not been tampered with.

Prerequisites

Before automating verification, ensure you have both tools installed and the sender's public key imported into your GPG keyring:

# Ubuntu/Debian
sudo apt install unrar gnupg

# Import the signer's public key
gpg --import public_key.asc

Method 1: Chaining Commands in Bash

The fastest way to extract and immediately verify is by chaining the unrar and gpg commands using the && operator. This ensures that the GPG check runs only if the extraction completes successfully.

Assuming your archive contains document.pdf and its detached signature document.pdf.sig:

unrar e archive.rar && gpg --verify document.pdf.sig document.pdf

Command Breakdown:

  • unrar e archive.rar: Extracts files to the current working directory without preserving directory paths (use x instead of e to retain full paths).
  • &&: Ensures the next command executes only if unrar returns an exit status of 0 (success).
  • gpg --verify document.pdf.sig document.pdf: Checks the signature against the extracted file.

If the signature file uses the default naming convention matching the target (e.g., file.ext and file.ext.sig), you can run:

unrar x archive.rar && gpg --verify file.ext.sig

Method 2: Verifying an Archive Before Extraction

If the entire RAR archive is signed rather than individual files inside it, verify the archive itself prior to extraction. This prevents malicious files from touching your disk entirely if the signature is invalid:

gpg --verify archive.rar.sig archive.rar && unrar x archive.rar

Method 3: Automated Bash Function

To handle this automatically for multiple archives, add a custom function to your ~/.bashrc or ~/.zshrc file:

unrar_verify() {
    local archive="$1"
    local target_file="$2"
    local sig_file="$3"

    if [ -z "$archive" ] || [ -z "$target_file" ] || [ -z "$sig_file" ]; then
        echo "Usage: unrar_verify <archive.rar> <target_file> <sig_file>"
        return 1
    fi

    unrar x "$archive" && gpg --verify "$sig_file" "$target_file"
}

Reload your shell configuration:

source ~/.bashrc

Run the automated command:

unrar_verify package.rar software.bin software.bin.asc

If the verification fails, GPG outputs a BAD signature error and returns a non-zero exit code, alerting you to compromised or corrupted data.