Downloads

Download

可验证信任的 KeePass 下载

KeePass 2.x ships as signed, hashed installers and portable packages mirrored on SourceForge - where community activity and download counters remain publicly visible. This page explains how to pin those artifacts to cryptographic evidence before rollout.

最新版本渠道概览

Dominik Reichl publishes KeePass 2.x for modern Windows systems (installer + portable ZIP), with translations and legacy packages documented on the official download matrix. Because release numbers advance frequently, always read the version banner on keepass.info/download.html before fetching binaries.

Windows 安装包

MSI-style deployment for managed desktops. Pair with Group Policy baseline hardening from the enterprise packaging guide.

在 keepass.info 下载

便携 ZIP

Unpack-and-run footprint for jump kits, air-gapped kiosks, and consultant laptops - no installer footprint on disk.

在 keepass.info 下载

语言包与附加组件

Language packs ship separately; verify checksums per bundle just like the core binary.

在 keepass.info 下载

源代码透明

KeePass remains GPLv2-licensed. Source archives accompany each release on official mirrors, enabling reproducible builds, diff reviews, and contributor audits. Supplemental repositories exist for translations and documentation, but cryptographic truth flows from Dominik Reichl’s signed release artifacts.

  • Review change logs before pushing a new MSI through SCCM or Intune.
  • Mirror internally only after verifying hashes against the public announcement.
  • Document which plugin versions ship with corporate gold images.

SHA-256 与 OpenPGP 签名

Why hashes matter

A published SHA-256 digest proves your downloaded bits match the bits the release engineer hashed. Store the digest alongside your internal change ticket so auditors can replay the verification months later.

Windows: Get-FileHash .\KeePass-2.xx.zip -Algorithm SHA256

macOS/Linux: shasum -a 256 KeePass-2.xx.zip

OpenPGP signature flow

Detached .sig files assert publisher identity when validated against the KeePass signing key distributed on the official site. Train administrators to import the trusted key once, pin its fingerprint, and reject packages signed by unknown identities - even if the filename looks correct.

Pair signature checks with TLS-protected downloads and internal artifact scanning for defense in depth.

杀毒软件误报

Security products sometimes flag KeePass or its plugins because installers bundle scripting hooks, auto-type components, or compressed executables resembling packers. This does not imply malware - it signals heuristic uncertainty. Follow the antivirus playbook: submit hashes to your vendor, temporarily quarantine in a sandbox, and only escalate after signature verification fails.

Security & integrity commitments

KeePass stores secrets using modern transforms documented in official security pages. Your download pipeline must preserve that assurance: verify signatures, restrict write access to deployment shares, and never sideload plugins from anonymous forums without code review.

下载