sha224sum writes a SHA-224 digest for a file, then a later check tells you whether the bytes still match. The examples use GNU coreutils 9.4, the version installed on the reference system.
sudo.Confirm that your shell will run the GNU utility described here:
$ sha224sum --version
sha224sum (GNU coreutils) 9.4
Your version may differ. The core workflow is stable, but keep the local help and manpage beside scripts that depend on less common options. SHA-224 produces a 224-bit digest, displayed as 56 hexadecimal characters.
Checkpoint: If sha224sum is not found, stop and install the package through your normal distribution process. Do not copy a checksum binary from an untrusted download.
Replace /path/to/important-file with a real readable path:
$ sha224sum /path/to/important-file
daf94d95cc268c8155076850c8ff30304408f3284888d2c5d41ff7e6 /path/to/important-file
The exact digest depends on the file. The final field is the file name. With no file argument, or with -, the command reads standard input:
$ printf '%s\n' 'alpha' 'beta' | sha224sum
daf94d95cc268c8155070c8ff30304408f3284888d2c5d41ff7e6 -
Input must be exact. A changed byte, line ending or trailing newline changes the digest. Quote paths containing spaces or shell metacharacters. The command reads its input; it does not rewrite it.
Run the calculation once and redirect standard output to a new checksum file:
$ sha224sum /path/to/important-file > /path/to/important-file.sha224
$ cat /path/to/important-file.sha224
daf94d95cc268c8155070c8ff30304408f3284888d2c5d41ff7e6 /path/to/important-file
Shell redirection truncates an existing destination before sha224sum starts. That is a destructive overwrite. Pick a new name, or preserve the old record first:
$ cp --preserve=all /path/to/important-file.sha224 /path/to/important-file.sha224.bak
$ sha224sum /path/to/important-file > /path/to/important-file.sha224.new
$ mv /path/to/important-file.sha224.new /path/to/important-file.sha224
The last command replaces the old record only after the new calculation succeeds. If the calculation fails, leave the original record in place and inspect the error. Remove the backup only after you have checked the new record; deletion is irreversible.
Ask --check to read the record and recalculate the named file:
$ sha224sum --check /path/to/important-file.sha224
/path/to/important-file: OK
An OK result means the current bytes match the recorded digest. It does not establish that the record itself came from a trusted source. Keep the checksum record separate from the file when you need an independent comparison.
For a script or quiet health check, use --status. It prints nothing, so inspect the exit status:
$ sha224sum --status /path/to/important-file.sha224
$ printf 'status=%s\n' "$?"
status=0
Do not treat empty output from --status as a failure. Status zero means every checked file matched; a non-zero status means the check failed or the checksum input was not usable.
Do not edit an important file merely to test an alert. Make a disposable copy, create its record, then alter the copy:
$ cp /path/to/important-file /tmp/important-file.test
$ sha224sum /tmp/important-file.test > /tmp/important-file.test.sha224
$ printf '%s\n' 'test change' >> /tmp/important-file.test
$ sha224sum --check /tmp/important-file.test.sha224
/tmp/important-file.test: FAILED
sha224sum: WARNING: 1 computed checksum did NOT match
The warning and exit status are the useful signals. Restore the disposable copy by removing both files when you have finished testing. Never use a broad recursive deletion command for cleanup; name only the temporary paths you created.
--text is the default and --binary does not change the bytes read. Use one consistently when exchanging records with another implementation, and check that implementation's rules rather than assuming all operating systems treat line endings alike.--tag emits a BSD-style line instead, such as SHA224 (/path/to/important-file) = ...; choose it for a consumer that explicitly requires that format.--zero terminates records with NUL rather than newline and disables filename escaping, useful for carefully designed machine pipelines but not a drop-in replacement for an ordinary checksum file.Options such as --quiet, --ignore-missing, --strict and --warn only matter when checking records. Read their local help before adding them to automation.
sha224sum --version identified the installed GNU coreutils release.sha224sum --check reports OK, or a script checks its non-zero failure status.