Skip to content

Verifying Your Download

Once you have downloaded the UMAI Engine installer from the useMango AI web app, you can check it before you install it. The linux installer is signed by useMango with a GPG signature, so verifying it proves the file came from us and has not been altered on the way to your machine.


What you need

You'll need gpg, sha256sum and curl to verify the download. sha256sum is always installed on Ubuntu, and if gpg or curl are missing you can install them with:

sudo apt install gnupg curl

useMango's public key

Key https://products.umai.pro/linux/umai-signing-key.asc
Fingerprint 35112356E04C228A91CE5DD6D2F9964C1D552209

Step 1: Get the checksums archive

Each release has a matching checksums archive, published alongside the installer. Run this in the directory you downloaded to:

curl -O https://products.umai.pro/linux/installers/UMAIEngineSetup-<version>-linux-x86_64.sums.tar.gz

The archive is named after the installer it covers, with .sums.tar.gz in place of .run. Take <version> from the installer you downloaded: for UMAIEngineSetup-1.4.2-linux-x86_64.run, the archive is UMAIEngineSetup-1.4.2-linux-x86_64.sums.tar.gz.

Inside are two files: SHA256SUMS, holding the checksum of the installer, and SHA256SUMS.asc, our signature over that checksum file.

Step 2: Import useMango's public key

Run this in the directory you downloaded to:

curl -O https://products.umai.pro/linux/umai-signing-key.asc
gpg --import umai-signing-key.asc

Step 3: Check the fingerprint

gpg --fingerprint 35112356E04C228A91CE5DD6D2F9964C1D552209

If the key you imported is ours, gpg prints its details. If it is not, gpg prints an error and finds nothing. Stop here and do not install the download.

The output also lists the key's subkeys. Releases are signed by a subkey, which is why the key ID in the next step's output differs from the fingerprint you just checked.

Step 4: Verify the signature on the checksums

tar -xzf UMAIEngineSetup-*.sums.tar.gz
gpg --verify SHA256SUMS.asc SHA256SUMS

Look for one line:

gpg: Good signature from ...

That is the check passing: SHA256SUMS is genuinely ours and has not been altered.

Two things in the output that look wrong but are not

"This key is not certified with a trusted signature!", or a [unknown] marker beside the user ID. gpg has no independent proof the key belongs to who it claims to. You supplied that proof yourself in step 3. The warning appears every time and is not a failure.

A key ID that does not match the fingerprint you checked. It belongs to the signing subkey rather than to the key itself. A good signature is a good signature.

If instead you see BAD signature, or Can't check signature: No public key, see If verification fails.

Step 5: Check the download against the checksums

sha256sum -c SHA256SUMS

Expect:

UMAIEngineSetup-<version>-linux-x86_64.run: OK

OK means the installer on your disk is exactly the file useMango signed, and the download is verified. If you see FAILED, delete the file and download it again.

Run step 4 before step 5

sha256sum -c only compares your file against whatever SHA256SUMS says. Verifying the signature first is what makes that checksum worth comparing against.


Install it

With both checks passed, install as normal:

chmod +x UMAIEngineSetup-<version>-linux-x86_64.run
./UMAIEngineSetup-<version>-linux-x86_64.run

If verification fails

A truncated download is far more likely than a tampered one. Work through these in order:

What you saw What it usually means
sha256sum reports FAILED The download did not complete cleanly. Download the installer again and repeat step 5.
Can't check signature: No public key The key import in step 2 did not take effect, or you are in a different directory. Repeat step 2.
gpg --fingerprint finds no such key The key you downloaded is not ours. Do not install the download.
BAD signature SHA256SUMS or SHA256SUMS.asc has been altered, or the archive did not download cleanly. Download the archive again and repeat step 4.

If the same failure repeats on a fresh download over a different network, contact useMango support before installing anything. Send the exact command output, which tells us which of the two checks failed.