Skip to content

RPM Basics

Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x

RPM (Red Hat Package Manager) is the low-level package management tool for EL systems. While DNF is more commonly used for everyday operations, understanding RPM basics is very helpful for querying package information, verifying package integrity, and troubleshooting issues.

  • RPM package naming format and structure
  • Querying installed package information with rpm
  • Installing and verifying RPM files
  • The relationship between RPM and DNF
  • GPG key verification mechanism
  • A system with EL 9.x installed
  • A user account with sudo privileges
  • Familiarity with DNF Basics

Each RPM package filename follows a fixed format:

name-version-release.architecture.rpm

Using nginx-1.24.0-1.el9.x86_64.rpm as an example:

PartValueDescription
NamenginxSoftware name
Version1.24.0Upstream software version
Release1.el9Package release, el9 indicates it is for EL 9
Architecturex86_64Target CPU architecture

RPM’s query capabilities are very powerful and are an essential troubleshooting tool. All query operations begin with rpm -q.

Check if nginx is installed
$ rpm -q nginx
nginx-1.24.0-1.el9.x86_64

If not installed, the output is:

package nginx is not installed
List all installed RPM packages on the system
$ rpm -qa
Filter with grep
$ rpm -qa | grep ssh
openssh-server-8.7p1-38.el9.x86_64
openssh-clients-8.7p1-38.el9.x86_64
openssh-8.7p1-38.el9.x86_64
Sort by installation time (most recently installed last)
$ rpm -qa --last | head -20
View detailed information about the nginx package
$ rpm -qi nginx

Example output:

Name : nginx
Version : 1.24.0
Release : 1.el9
Architecture: x86_64
Install Date: Mon 24 Mar 2026 10:00:00 AM CST
Group : System Environment/Daemons
Size : 1918738
License : BSD
Signature : RSA/SHA256, Fri 15 Nov 2025 08:00:00 AM CST, Key ID ...
Source RPM : nginx-1.24.0-1.el9.src.rpm
Build Date : Fri 15 Nov 2025 06:00:00 AM CST
Build Host : build.almalinux.org
URL : https://nginx.org/
Summary : A high performance web server and reverse proxy server
Description : Nginx is a web server and a reverse proxy server...
View the files installed by the nginx package
$ rpm -ql nginx

Example output:

/etc/logrotate.d/nginx
/etc/nginx
/etc/nginx/conf.d
/etc/nginx/conf.d/default.conf
/etc/nginx/nginx.conf
/usr/lib/systemd/system/nginx.service
/usr/sbin/nginx
/usr/share/nginx/html/index.html
...
Find which RPM package owns a file
$ rpm -qf /usr/sbin/nginx
nginx-1.24.0-1.el9.x86_64
Find which package owns a configuration file
$ rpm -qf /etc/ssh/sshd_config
openssh-server-8.7p1-38.el9.x86_64
List the configuration files of the nginx package
$ rpm -qc nginx

Example output:

/etc/logrotate.d/nginx
/etc/nginx/conf.d/default.conf
/etc/nginx/fastcgi.conf
/etc/nginx/nginx.conf
...
List the documentation files of the nginx package
$ rpm -qd nginx
View the dependencies of nginx
$ rpm -qR nginx
View which packages depend on openssl-libs
$ rpm -q --whatrequires openssl-libs

Adding the -p parameter to the query commands above lets you query .rpm files that have not been installed:

View information about an uninstalled RPM file
$ rpm -qip ./some-package-1.0-1.el9.x86_64.rpm
List the files contained in an uninstalled RPM file
$ rpm -qlp ./some-package-1.0-1.el9.x86_64.rpm
CommandDescription
rpm -qaList all installed packages
rpm -q <package>Check if a package is installed
rpm -qi <package>View detailed package information
rpm -ql <package>List all files installed by a package
rpm -qf <file-path>Find which package owns a file
rpm -qc <package>List a package’s configuration files
rpm -qd <package>List a package’s documentation files
rpm -qR <package>View a package’s dependencies
rpm -q --lastList packages sorted by installation time
Install a local RPM file using rpm
$ sudo rpm -ivh package-1.0-1.el9.x86_64.rpm

Parameter descriptions:

  • -i: Install
  • -v: Verbose output
  • -h: Show progress bar
Section titled “Recommended: Use DNF to Install Local RPMs”
Install a local RPM file using DNF (automatic dependency resolution)
$ sudo dnf install ./package-1.0-1.el9.x86_64.rpm
Upgrade an installed package
$ sudo rpm -Uvh package-1.1-1.el9.x86_64.rpm

The -U parameter behavior: if the package is already installed it upgrades; if not installed it installs.

Remove an installed package
$ sudo rpm -e nginx
Verify whether files from the nginx package have been modified
$ rpm -V nginx

If all files are intact, the command produces no output. If files have been modified, modification markers are displayed:

S.5....T. c /etc/nginx/nginx.conf

Marker meanings:

MarkerDescription
SFile size changed
MPermissions or file type changed
5MD5 checksum changed
DDevice number changed
LSymbolic link changed
UOwner changed
GGroup changed
TModification time changed
PCapabilities changed
Verify all installed packages
$ rpm -Va

RPM uses GPG signatures to ensure package authenticity and integrity.

List GPG keys imported into the RPM database
$ rpm -qa gpg-pubkey*
View details of a specific key
$ rpm -qi gpg-pubkey-xxxxxxxx-yyyyyyyy
Import a repository's GPG public key
$ sudo rpm --import https://www.example.com/RPM-GPG-KEY-example
Import a local GPG public key file
$ sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-9
Verify the GPG signature of an RPM file
$ rpm -K package-1.0-1.el9.x86_64.rpm

Example output (valid signature):

package-1.0-1.el9.x86_64.rpm: digests signatures OK

Example output (invalid signature or key not imported):

package-1.0-1.el9.x86_64.rpm: digests SIGNATURES NOT OK

Understanding the division of responsibilities between RPM and DNF is important:

FeatureRPMDNF
Install local .rpm filesSupportedSupported
Automatic dependency resolutionNot supportedSupported
Download and install from repositoriesNot supportedSupported
Query package informationSupportedSupported
Verify file integritySupportedNot supported
GPG signature verificationSupportedSupported (calls RPM)

In summary:

  • DNF is the high-level package manager, responsible for repository management, dependency resolution, and downloading
  • RPM is the low-level package manager, responsible for the actual package installation, querying, and verification
  • DNF calls RPM under the hood to perform package installation and removal

For daily use, it is recommended to use DNF for installing, updating, and removing packages, and RPM for querying and verification.

rpm -ivh Reports “Failed dependencies”

Section titled “rpm -ivh Reports “Failed dependencies””

This means the package has unmet dependencies. Solution:

Recommended: use DNF to install the local RPM
$ sudo dnf install ./package.rpm
Use DNF provides to search
$ dnf provides */bin/dig

Example output:

bind-utils-9.16.23-14.el9.x86_64 : Utilities for querying DNS name servers
Repo : baseos
Matched from:
Filename : /usr/bin/dig

How to Extract Files from an RPM Package (Without Installing)

Section titled “How to Extract Files from an RPM Package (Without Installing)”
Extract files using rpm2cpio
$ rpm2cpio package.rpm | cpio -idmv