SHA256SUMS and JWT signatures: what verification can prove
Separate file hashes, JWT signatures and identity trust. Reconcile missing and extra files in SHA256SUMS and understand the limits of local HAR, robots and CSP checks.
Example: receive files and an access token
A release package contains a PDF, a data export and a short configuration note. The sender wants the recipient to know that the files arrived unchanged. A SHA256 manifest can answer that byte-level question. It cannot, by itself, establish who sent the package or whether the content is safe or correct. That distinction determines how the expected manifest should be obtained and stored.
Separate matching bytes from trusted sources
Generate the manifest from the final bytes, then preserve it through a trusted channel. During verification, inspect all three result classes: mismatched files, missing filenames and files not listed in the manifest. Renaming a file may leave its digest unchanged while breaking the name-based lookup. A green result for one file is not an acceptance check for the entire package.
Check files, signatures and configuration separately
Apply the same separation of claims to authentication and web configuration. Decoding a JWT only reveals its structure. Signature verification additionally needs a trusted key and a pinned algorithm, while issuer, audience and time checks answer different questions. Similarly, an offline CSP inspection or robots rule test can reveal a local configuration issue without proving what a deployed browser or crawler actually receives.
SHA-256 of an empty file starts e3b0c442; a filename change does not change its bytes, but a manifest lookup still requires the exact name.Record conditions and unresolved checks
Before sharing a diagnostic report, inspect the report itself. A HAR summary omits query values, headers, cookies and bodies, but its URL path can still identify a customer or internal project. Keep credentials out of examples and compare full fingerprints through an independent source. Local execution reduces upload exposure; it does not remove the need to control what you copy, download or send to another person.
| Do not rely only on | Also check |
|---|---|
| Matching hashes | Establish a trusted source for the expected manifest |
| A valid JWT signature | Check time, issuer, audience and application authorization |
| Local rules pass | Check actual deployed responses and configuration |
- Record mismatched, missing and unlisted files separately.
- Do not confuse decoded claims with a verified signature.
- Review URL paths before sharing a HAR summary.
References
- Encoding, signatures and file integrity
Reference for the relevant format and processing rules.
- Local website checks before release
Reference for the relevant format and processing rules.
- Network ranges and allowlist review
Reference for the relevant format and processing rules.