MonetDB Download Area

Icon  Name                    Last modified      Size  Description
[PARENTDIR] Parent Directory - [DIR] Fedora/ 2017-08-10 13:33 - MonetDB Fedora RPMs & YUM repository [DIR] FreeBSD/ 2017-08-02 10:04 - MonetDB FreeBSD installers [DIR] Java-Experimental/ 2017-08-16 13:31 - MonetDB Java interfacing: JDBC driver & JdbcClient app [DIR] Java/ 2017-07-28 09:47 - MonetDB Java interfacing: JDBC driver & JdbcClient app [DIR] MacOSX/ 2017-08-02 10:04 - MonetDB Mac OS X installers [   ] MonetDB-GPG-KEY 2017-08-03 12:28 6.6K MonetDB public key [DIR] PHP/ 2016-12-21 14:06 - [DIR] Perl/ 2016-12-21 14:06 - [DIR] Python/ 2017-07-04 12:41 - [DIR] Solaris/ 2017-06-12 14:49 - MonetDB Solaris installers [DIR] Windows/ 2017-08-02 10:04 - MonetDB Windows installers [DIR] archive/ 2015-10-20 13:05 - Old MonetDB distributions [DIR] deb/ 2017-08-02 17:42 - MonetDB Debian and Ubuntu repository [DIR] epel/ 2017-08-10 17:01 - MonetDB EPEL (Red Hat, CentOS, Scientific Linux) RPMs & YUM repository [DIR] ruby/ 2016-09-14 14:18 - [DIR] sources/ 2017-08-02 10:04 - MonetDB source distributions [DIR] testing/ 2017-07-27 15:13 - MonetDB release candidates

In various directories there is a file SHA256SUM which contains the sha256 checksum of the files in that directory. This SHA256SUM file is signed using the key of which the public part is available in the file MonetDB-GPG-KEY.

Starting August 2017, i.e. releases after the Jul2017-SP1 release, new signatures will be created using a new key with key ID 0xDF0E54F3. Both the old and the new key are in the above mentioned file. The old key has key ID 0x0583366F.

The keys are also available from keyservers:

gpg --recv-key 0x0583366F 0xDF0E54F3

You should check the fingerprint of the keys:

gpg --fingerprint 0x0583366F 0xDF0E54F3

The fingerprint are: 213E 64DC D5DD C2C0 63CC 39FD 053C 3ED4 0583 366F for the old key (key ID 0x0583366F) and 8289 A5F5 75C4 9F50 22F8 EE20 F654 63E2 DF0E 54F3 for the new key (key ID 0xDF0E54F3).

You can then download the SHA256SUM file and check that it hasn't been tampered with:

gpg --verify SHA256SUM

Among other output, you should see the message

gpg: Good signature from "MonetDB Database System Packager <monet@cwi.nl>"


gpg: Good signature from "MonetDB Database System Packager <info@monetdb.org>"

You should also see the message that the signature was made using the DSA key ID 0583366F or RSA key ID DF0E54F3 (the old and new key ID).

After this, you can verify that the downloaded files are correct:

sha256sum --check SHA256SUM

For all files you downloaded, you should see the name of the file followed by the work "OK".

In addition, all RPM files and DEB packages are also signed with one of the keys. See the Fedora, epel (for Enterprise Linux), and deb (for Debian and Ubuntu) directories for more details.

Further information about the "Jul2017-SP1" release is available in the release notes.