Verifying Your Download
Once you have downloaded the UMAI Engine installer from the useMango AI web app, you can check it before you install it. The linux installer is signed by useMango with a GPG signature, so verifying it proves the file came from us and has not been altered on the way to your machine.
What you need
You'll need gpg, sha256sum and curl to verify the download. sha256sum is always installed
on Ubuntu, and if gpg or curl are missing you can install them with:
sudo apt install gnupg curl
useMango's public key
| Key | https://products.umai.pro/linux/umai-signing-key.asc |
| Fingerprint | 35112356E04C228A91CE5DD6D2F9964C1D552209 |
Step 1: Get the checksums archive
Each release has a matching checksums archive, published alongside the installer. Run this in the directory you downloaded to:
curl -O https://products.umai.pro/linux/installers/UMAIEngineSetup-<version>-linux-x86_64.sums.tar.gz
The archive is named after the installer it covers, with .sums.tar.gz in place of .run. Take
<version> from the installer you downloaded: for UMAIEngineSetup-1.4.2-linux-x86_64.run, the
archive is UMAIEngineSetup-1.4.2-linux-x86_64.sums.tar.gz.
Inside are two files: SHA256SUMS, holding the checksum of the installer, and
SHA256SUMS.asc, our signature over that checksum file.
Step 2: Import useMango's public key
Run this in the directory you downloaded to:
curl -O https://products.umai.pro/linux/umai-signing-key.asc
gpg --import umai-signing-key.asc
Step 3: Check the fingerprint
gpg --fingerprint 35112356E04C228A91CE5DD6D2F9964C1D552209
If the key you imported is ours, gpg prints its details. If it is not, gpg prints an error and
finds nothing. Stop here and do not install the download.
The output also lists the key's subkeys. Releases are signed by a subkey, which is why the key ID in the next step's output differs from the fingerprint you just checked.
Step 4: Verify the signature on the checksums
tar -xzf UMAIEngineSetup-*.sums.tar.gz
gpg --verify SHA256SUMS.asc SHA256SUMS
Look for one line:
gpg: Good signature from ...
That is the check passing: SHA256SUMS is genuinely ours and has not been altered.
Two things in the output that look wrong but are not
"This key is not certified with a trusted signature!", or a [unknown] marker beside the
user ID. gpg has no independent proof the key belongs to who it claims to. You supplied that
proof yourself in step 3. The warning appears every time and is not a failure.
A key ID that does not match the fingerprint you checked. It belongs to the signing subkey rather than to the key itself. A good signature is a good signature.
If instead you see BAD signature, or Can't check signature: No public key, see
If verification fails.
Step 5: Check the download against the checksums
sha256sum -c SHA256SUMS
Expect:
UMAIEngineSetup-<version>-linux-x86_64.run: OK
OK means the installer on your disk is exactly the file useMango signed, and the download is
verified. If you see FAILED, delete the file and download it again.
Run step 4 before step 5
sha256sum -c only compares your file against whatever SHA256SUMS says. Verifying the
signature first is what makes that checksum worth comparing against.
Install it
With both checks passed, install as normal:
chmod +x UMAIEngineSetup-<version>-linux-x86_64.run
./UMAIEngineSetup-<version>-linux-x86_64.run
If verification fails
A truncated download is far more likely than a tampered one. Work through these in order:
| What you saw | What it usually means |
|---|---|
sha256sum reports FAILED |
The download did not complete cleanly. Download the installer again and repeat step 5. |
Can't check signature: No public key |
The key import in step 2 did not take effect, or you are in a different directory. Repeat step 2. |
gpg --fingerprint finds no such key |
The key you downloaded is not ours. Do not install the download. |
BAD signature |
SHA256SUMS or SHA256SUMS.asc has been altered, or the archive did not download cleanly. Download the archive again and repeat step 4. |
If the same failure repeats on a fresh download over a different network, contact useMango support before installing anything. Send the exact command output, which tells us which of the two checks failed.