Create and Verify SHA-512 Checksums with sha512sum
You will finish with a SHA-512 checksum for a file, a checksum list that can be checked later, and a way to distinguish a changed file from a missing or badly formatted entry. The examples use GNU sha512sum from coreutils 9.4, installed here as package version 9.4-3ubuntu6.3.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and read access to the files you want to check. The normal commands are unprivileged. Do not use sudo to hash a file unless its permissions genuinely require it: elevated access does not make a checksum more trustworthy.
1. Check the installed command
Confirm which executable your shell will run and record its version:
$ command -v sha512sum
/usr/bin/sha512sum
$ sha512sum --version | head -1
sha512sum (GNU coreutils) 9.4
This guide follows the GNU implementation documented by the local sha512sum(1) manual. It prints a 512-bit digest, normally as 128 hexadecimal characters, followed by the file name. With no file argument, or with -, it reads standard input.
Checkpoint: if command -v finds another implementation, read that implementation's manual before putting its output into an automated verification process.
2. Hash one file
Point the command at a readable file. This example hashes an existing download; replace the path with your own file:
$ sha512sum /path/to/download.iso
7bc2bf47a91fcb298f66fee07082a4a8cf57b71c9034fefd23e49608e96c23dfa37947f4159acb9498a907e47767f052f6a948edb43b309b9786631a58d5ec41 /path/to/download.iso
Compare the digest character for character with the value published by a source you trust. A successful command only says that the file was read and hashed. It does not say that the file came from the expected source, so obtain the reference checksum through a separately trusted channel.
For a pipeline, send data to standard input:
$ printf '%s\n' 'abc' | sha512sum
4f285d0c0cc77286d8731798b7aae2639e28270d4166f40d769cbbdca5230714d848483d364e2f39fe6cb9083c15229b39a33615ebc6d57605f7c43f6906739d -
The trailing - identifies standard input. The newline supplied by printf is part of the data, so changing the input even slightly changes the digest.
3. Save a checksum list
A checksum list is useful when a directory contains several files or when you will verify the same file later. Run this from the directory containing the file:
$ sha512sum download.iso > SHA512SUMS
$ cat SHA512SUMS
7bc2bf47a91fcb298f66fee07082a4a8cf57b71c9034fefd23e49608e96c23dfa37947f4159acb9498a907e47767f052f6a948edb43b309b9786631a58d5ec41 download.iso
The redirection creates or replaces SHA512SUMS. That is ordinary file modification, not an elevated operation. Warning: > truncates an existing file before sha512sum runs. Choose a new name, or use a temporary list and replace the old one only after checking it:
$ sha512sum download.iso > SHA512SUMS.new
$ sha512sum --check SHA512SUMS.new
download.iso: OK
$ mv SHA512SUMS.new SHA512SUMS
If the command fails, leave the old list in place and inspect the error. Recovery is simply to remove the unneeded SHA512SUMS.new after confirming that it contains no useful entry.
4. Verify the list
Give the list to --check. The command reads each recorded path, hashes the current file, and reports the result:
$ sha512sum --check SHA512SUMS
download.iso: OK
An altered file produces a failure report and a non-zero exit status. A missing file is also a failure by default. The list must be available before you begin: it is the reference, not something that should be regenerated after a failed check.
For scripts, use --status when the exit status is all you need:
$ sha512sum --check --status SHA512SUMS
$ printf '%s\n' "$?"
0
--quiet is a readable alternative that suppresses the OK line but still reports failures. Do not use --ignore-missing for release or backup verification unless missing files are deliberately outside the check. It changes a missing file from a reported failure into an ignored case.
5. Understand text, binary and list formats
GNU systems have no difference between the command's text and binary reading modes, so -t is the default and -b is normally equivalent. The output marker can still differ: text mode uses a space before the file name, while binary mode uses *. Keep the mode consistent when exchanging checksum lists with other tools or operating systems.
--tag writes a BSD-style record instead:
$ sha512sum --tag download.iso
SHA512 (download.iso) = 7bc2bf47a91fcb298f66fee07082a4a8cf57b71c9034fefd23e49608e96c23dfa37947f4159acb9498a907e47767f052f6a948edb43b309b9786631a58d5ec41
Use the ordinary output when you want a list that sha512sum --check can consume. The manual describes checking input as a former output of this program, so do not hand-edit the format casually.
6. Handle filenames and malformed lists
Filenames containing unusual characters can be escaped in normal output. --zero instead terminates each output record with a NUL byte and disables filename escaping, which is useful when another program is deliberately reading NUL-delimited records. It is not a substitute for understanding that program's input format.
When checking untrusted or hand-written lists, add --strict if improperly formatted lines must make the command fail. --warn reports malformed lines without making that format check the main result. Test a list without changing it:
$ sha512sum --check --strict SHA512SUMS
download.iso: OK
$ printf '%s\n' "$?"
0
Do not treat a warning about formatting as proof that every intended file was checked. Inspect the list, confirm its paths, and use a non-zero status as a stop signal in automation.
Done means
sha512sum --versionidentifies the implementation you are using.- The digest was compared with a trusted reference, not merely generated.
- The saved list remains separate from the files it verifies.
sha512sum --checkreportsOKfor every required file and exits with status 0.- Missing, changed or malformed entries are not hidden with permissive options.