4 Step‐by‐step: Temurin reproducible verification instructions for Windows x64
Andrew Leonard edited this page 2026-04-16 09:02:50 +01:00
  1. Securely create or use your existing securely created Windows ReDist DevKit DLL package (creation instructions). Your ReDist DevKit DLL zip file can either be downloaded to your Windows x64 build machine, or referenced by URL should you have it in an accessible location.
  2. Setup the required VS2022 toolchain on your Windows x64 build machine (instructions)
  3. Ensure Windows system Time zone is UTC to ensure an identical build (Set the Windows "Time zone" to UTC, by checking the Windows Settings→"Time & Language" → "Date & time" → "Time zone" value). Re-boot the Windows machine after changing the Time Zone.
  4. Ensure "Cygwin" is installed. If not, the following instructions can be used to securely install it :
curl -L -O https://cygwin.com/setup-x86_64.exe
curl -l -O https://cygwin.com/setup-x86_64.exe.sig
# Verify download: Import "Cygwin <cygwin@cygwin.com>" GPG key
gpg --keyserver keyserver.ubuntu.com --recv-keys 1A698DE9E2E56300
gpg --verify setup-x86_64.exe.sig setup-x86_64.exe
# Check for “Good signature” ??

setup-x86_64.exe --packages autoconf,automake,bsdtar,cmake,cpio,curl,gcc-core,git,gnupg,grep,jq,libtool,make,mingw64-x86_64-gcc-core,perl,rsync,unzip,wget,zip --download --local-install --delete-orphans --site https://mirrors.kernel.org/sourceware/cygwin/ --local-package-dir C:\cygwin_packages --root C:\cygwin64
  1. Clone the Adoptium community temurin-build repository containing the Windows reproducible verification script:
git clone https://github.com/adoptium/temurin-build.git
  1. Determine the published Adoptium Temurin build that is to be verified, and determine the Adoptium API URLs for the JDK and SBOM for that version, eg.for release Temurin jdk-25.0.2+10 :
JDK_URL: "https://api.adoptium.net/v3/binary/version/jdk-25.0.2+10/windows/x64/jdk/hotspot/normal/eclipse?project=jdk"
SBOM_URL: "https://api.adoptium.net/v3/binary/version/jdk-25.0.2+10/windows/x64/sbom/hotspot/normal/eclipse?project=jdk"
  1. Obtain either the REDIST_DEVKIT_URL or location of your securely created Windows ReDist DLL DevKit zip file, or the full file path to its location if local to your machine.
  2. Run the temurin-build "windows_repro_build_compare.sh" script to verify the build is 100% reproducible, specifying the required option values determined above :
cd temurin-build/blob/master/tooling/reproducible
mkdir report
bash ./windows_repro_build_compare.sh --sbom-url [SBOM_URL] --jdk-url [JDK_URL] --report-dir report --user-devkit-location [REDIST_DEVKIT_URL|LOCATION] --reproducible-verification
  1. If all is successful, the script should report the Temurin reproducible verification is 100% identical.