# Error: no checksum found in: ... in "file:..." (Packer iso_checksum)

## TL;DR
The checksum file is not in a format Packer's parser understands (PGP-signed, commented, or header lines). Download the file, extract the raw `[sha] [filename]` line, and use `sha256:[hash]` directly instead of `file:`.

## The error

```
Error: 1 error(s) occurred:

* no checksum found in: http://channels.nixos.org/nixos-21.11/latest-nixos-minimal-x86_64-linux.iso.sha256 in "file:http://channels.nixos.org/nixos-21.11/latest-nixos-minimal-x86_64-linux.iso.sha256"
```

## Fix it

1. Download the checksum file and inspect it: look for `-----BEGIN PGP SIGNED MESSAGE-----`, `#` comments, or `SHA256 (...)` BSD-style lines.
   - Success check: you see why the parser choked.
2. Extract the GNU-style line (`[hash]  [filename]`) for your ISO. If the file is PGP-signed, strip the signature armor first.
   - Success check: you have a bare hex hash.
3. Set `iso_checksum = "sha256:[hash]"` (or `sha1:`, `sha512:`, `md5:` to match) instead of `file:`.
   - Success check: `packer validate` passes.
4. Re-run `packer build`.
   - Success check: the ISO verifies and the build proceeds.

## When to use this
You hit this at `packer validate` with `iso_checksum = "file:[url]"` where the remote file is PGP-signed or otherwise non-GNU.

## When NOT to use this
Do not use this for `Error downloading checksum file` (network failure fetching the file) or for hash *mismatches* (wrong hash, right format).

## Compatibility
Packer 1.x, go-getter checksum parsing. Affects Red Hat-family mirrors especially.

## Variants
- `no checksum found in:` naming Fedora/CentOS/RHEL CHECKSUM files
- BSD-style `SHA256 (file) = hash` lines (four words; sometimes parsed, sometimes not)

## Root cause
Go-getter's checksum parser only handles lines with exactly two (GNU), four (BSD), or zero words. PGP armor, comments, and `Hash:` headers produce lines it cannot parse, so it reports no checksum found.

## Edge cases
- Some mirrors serve different formats per release. Re-check the file format when you bump versions.
- `none` disables verification entirely; acceptable for trusted local ISOs, not for downloads.
