How to Unrar and Verify GPG Signatures
This article explains how to extract files from a RAR archive and
automatically verify their authenticity using GNU Privacy Guard (GPG).
Because the unrar utility does not have built-in
cryptographic verification tools, combining unrar with
gpg via shell commands or automation scripts provides a
seamless, secure workflow to ensure extracted contents have not been
tampered with.
Prerequisites
Before automating verification, ensure you have both tools installed and the sender's public key imported into your GPG keyring:
# Ubuntu/Debian
sudo apt install unrar gnupg
# Import the signer's public key
gpg --import public_key.ascMethod 1: Chaining Commands in Bash
The fastest way to extract and immediately verify is by chaining the
unrar and gpg commands using the
&& operator. This ensures that the GPG check runs
only if the extraction completes successfully.
Assuming your archive contains document.pdf and its
detached signature document.pdf.sig:
unrar e archive.rar && gpg --verify document.pdf.sig document.pdfCommand Breakdown:
unrar e archive.rar: Extracts files to the current working directory without preserving directory paths (usexinstead ofeto retain full paths).&&: Ensures the next command executes only ifunrarreturns an exit status of0(success).gpg --verify document.pdf.sig document.pdf: Checks the signature against the extracted file.
If the signature file uses the default naming convention matching the
target (e.g., file.ext and file.ext.sig), you
can run:
unrar x archive.rar && gpg --verify file.ext.sigMethod 2: Verifying an Archive Before Extraction
If the entire RAR archive is signed rather than individual files inside it, verify the archive itself prior to extraction. This prevents malicious files from touching your disk entirely if the signature is invalid:
gpg --verify archive.rar.sig archive.rar && unrar x archive.rarMethod 3: Automated Bash Function
To handle this automatically for multiple archives, add a custom
function to your ~/.bashrc or ~/.zshrc
file:
unrar_verify() {
local archive="$1"
local target_file="$2"
local sig_file="$3"
if [ -z "$archive" ] || [ -z "$target_file" ] || [ -z "$sig_file" ]; then
echo "Usage: unrar_verify <archive.rar> <target_file> <sig_file>"
return 1
fi
unrar x "$archive" && gpg --verify "$sig_file" "$target_file"
}Reload your shell configuration:
source ~/.bashrcRun the automated command:
unrar_verify package.rar software.bin software.bin.ascIf the verification fails, GPG outputs a BAD signature
error and returns a non-zero exit code, alerting you to compromised or
corrupted data.