# Error: Error downloading checksum file: ... read: connection reset by peer (Packer)

## TL;DR
The checksum file download was interrupted. Retry the build, and if the mirror is flaky, pin the hash directly (`sha256:[hash]`) so no download is needed.

## The error

```
Error: 1 error(s) occurred:

* Error downloading checksum file: Get "https://cloud-images.ubuntu.com/releases/22.04/release-20230815/SHA256SUMS": read tcp CONTAINER_IP:35328->185.12.5.190.37:443: read: connection reset by peer in "file:https://cloud-images.ubuntu.com/releases/22.04/release-20230815/SHA256SUMS"
```

## Fix it

1. Retry `packer validate` / `packer build`. Connection resets are often transient.
   - Success check: the checksum downloads on retry.
2. If it keeps failing, fetch the checksum file yourself with `curl` and confirm the mirror is reachable.
   - Success check: you can download it outside Packer.
3. For reliability, pin the hash: replace `iso_checksum = "file:[url]"` with `iso_checksum = "sha256:[hash]"` using the hash from the file.
   - Success check: no network fetch happens at validate time.
4. In CI, cache the checksum file or the hash in a variable file so builds do not depend on the mirror.
   - Success check: builds are hermetic.

## When to use this
You hit this at validate time when the `file:` checksum URL is unreachable or flaky.

## When NOT to use this
Do not use this for `no checksum found in:` (the file downloaded but could not be parsed) or for hash mismatches.

## Compatibility
Packer 1.x, any builder using `iso_checksum = "file:..."`.

## Variants
- `Error downloading checksum file` with DNS failures, 403s, or timeouts instead of resets
- The build continuing past a failed checksum download in some versions (then failing later at ISO verification)

## Root cause
`file:` checksums require a network fetch at validate time. Any interruption (reset, timeout, mirror outage) fails validation before the build starts.

## Edge cases
- Parallel builds (`-parallel-builds=8`) multiply the fetch load and the flake rate. Pinning the hash helps most there.
- IPv6-only or proxied CI runners may fail where your laptop succeeds. Test from the runner.
