Every released or patch version of the downloadable product packages from VMware comes with its MD5 and SHA1 checksums in the VMware Customer Connect portal. The checksums can be used to verify if the downloaded file is intact, and in its original form. The above statement also applies to vRealize Operations installation PAK files (for cluster and cloud proxy upgrade, management packs, content packs, compliance packs, and so on).
Integrity Check from Untrusted Sources
If there is a lack of information about the download source, the digital signature of vRealize Operations installation PAK files can be verified manually before applying it. You can run the following steps to verify if the package contents have the correct signature by the trusted certificate