A Windows .exe or DLL arrives claiming to be signed, and chktrust tells you whether that claim holds up on Linux. It checks that a PE file has an intact Authenticode signature chaining to a certificate authority in Mono's trust store. This guide uses the chktrust shipped by mono-devel version 6.8.0.105+dfsg-3.6ubuntu2 and takes about ten minutes.
Check which executable your shell will run, then ask it for its help text:
$ command -v chktrust
/usr/bin/chktrust
$ chktrust -h
Mono CheckTrust - version 6.8.0.105
Verify if an PE executable has a valid Authenticode(tm) signature
...
Usage: chktrust [options] filename
The installed command takes one filename after its options. Its manpage describes the target as a PE executable, including a CLR assembly, Win32 executable or DLL. Do not use it as a general checksum checker: it looks for an Authenticode signature and its certificate chain.
Tip: for a reproducible record, capture the package version as well.
$ dpkg-query -W -f='${Package} ${Version}\n' mono-devel
mono-devel 6.8.0.105+dfsg-3.6ubuntu2
Replace the placeholder with the path to the file you received. The command reads the file and reports its result:
$ chktrust /path/to/program.exe
Mono CheckTrust - version 6.8.0.105
Verify if an PE executable has a valid Authenticode(tm) signature
...
Verifying file program.exe for Authenticode(tm) signatures...
WARNING! program.exe is not timestamped!
ERROR! program.exe doesn't contain a digital signature!
The banner and filename formatting can vary slightly. A missing-timestamp warning is a separate diagnostic, not a valid signature. The decisive line in this example is that the file has no digital signature, and the command exits non-zero.
Capture the status straight after the check:
$ chktrust /path/to/program.exe
$ status=$?
$ printf 'chktrust exit status: %s\n' "$status"
chktrust exit status: 1
Do not run another command before saving $?. This example uses an unsigned file, so status 1 is what the installed version returned.
Warning: treat a non-zero result as a failed trust check unless you have read the actual diagnostic and your process explicitly allows that outcome.
The manpage documents -q or -quiet as quiet mode and -v or -verbose as verbose mode. Test the installed build's exact behaviour before putting either option into automation:
$ chktrust -v /path/to/program.exe
Mono CheckTrust - version 6.8.0.105
...
Verifying file program.exe for Authenticode(tm) signatures...
...
$ printf 'status: %s\n' "$?"
status: 1
-q still prints the normal banner and diagnostics for an unsigned file.Use the long forms when someone unfamiliar with Mono will review the command:
$ chktrust --quiet /path/to/program.exe
$ check_status=$?
$ if [ "$check_status" -eq 0 ]; then
> printf '%s\n' 'signature accepted'
> else
> printf 'signature check failed: status %s\n' "$check_status" >&2
> exit "$check_status"
> fi
signature check failed: status 1
chktrust checks two linked conditions. The signature must be valid, which protects the signed content from alteration. The signing certificate must also chain to a trusted certificate authority in the trust store. Passing the first alone is not enough, because a certificate can be present while its chain is untrusted on this host.
That trust store is part of the result, so a signed file can fail on one machine and pass on another if their Mono certificate stores differ. A failure saying the signature cannot be traced to a trusted root is not evidence the file was modified. It means the trust decision is incomplete on this system. Record the diagnostic, then look into the publisher certificate and your intended trust policy through your normal software-supply-chain process.
Security warning: do not import a certificate merely to make a check pass. Adding a root or intermediate certificate changes future trust decisions for Mono applications. If your organisation has approved a certificate, use its documented certificate-management procedure and record the change. This guide does not alter the trust store, install certificates or grant elevated privileges.
Check the path and permissions before diagnosing signature output:
$ ls -l -- /path/to/program.exe
$ test -r /path/to/program.exe && echo 'readable'
readable
A missing or unreadable file is an input problem, not a certificate result. Fix the path or access through the owner-approved process, then rerun. Use sudo only if the file genuinely needs elevated read access and local policy permits it, and never run the whole shell as root.
Know the limits:
For a local smoke test, the installed Mono assembly below is a PE file but is unsigned on this machine:
$ chktrust /usr/lib/mono/4.5/mscorlib.dll
WARNING! mscorlib.dll is not timestamped!
ERROR! mscorlib.dll doesn't contain a digital signature!
$ printf 'status: %s\n' "$?"
status: 1
That shows the command is available and can inspect a CLR assembly. It does not replace testing the file you actually intend to run.
Tip: keep the original file unchanged while you investigate a failed trust check. These read-only examples leave no state to undo.
chktrust resolves to the expected executable and its Mono version is recorded.