64-bit
wixmachine scopegithub.com · known platform- File name
- OpenJDK21U-jdk_x64_windows_hotspot_21.0.12_8.msi
- SHA-256
- 845a30ebafdb4cbc4aff9c9d65b574a3dd154fbc5ef7f9412cd26628ffa5c22d
by Eclipse Adoptium · GPL-2.0 with Classpath Exception
Eclipse Temurin JDK is the open source Java SE build based upon OpenJDK.
These URLs are the ones Eclipse Adoptium declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what Eclipse Adoptium published. Delete it.
Windows · PowerShell
Get-FileHash "OpenJDK21U-jdk_x64_windows_hotspot_21.0.12_8.msi" -Algorithm SHA256macOS · Linux
shasum -a 256 "OpenJDK21U-jdk_x64_windows_hotspot_21.0.12_8.msi"Expected output
845a30ebafdb4cbc4aff9c9d65b574a3dd154fbc5ef7f9412cd26628ffa5c22d
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
This installer is an MSI package, so it takes the standard Windows Installer switches. That is a property of MSI itself rather than something the publisher declared.
64-bit · machine scope · MSI convention
msiexec /i "OpenJDK21U-jdk_x64_windows_hotspot_21.0.12_8.msi" /qn /norestartRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 1 of 1 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 1 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 1 of 1 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 1 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | GPL-2.0 with Classpath ExceptionA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions Eclipse Temurin JDK with Hotspot 21 registers itself to handle.
The installer comes from a recognised distribution platform rather than Eclipse Adoptium's own domain. That is normal for this kind of software and not a red flag by itself.
The installer on this page comes with the SHA-256 Eclipse Adoptium declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 95/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id EclipseAdoptium.Temurin.21.JDK --exactUpgrade later
winget upgrade --id EclipseAdoptium.Temurin.21.JDKWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of Eclipse Temurin JDK with Hotspot 21, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
93A9C20F4CE967D78992EDC5E6FDCC250A56019080553D5D20846DECB51D9C01
6BE8643444EC20758A34DDB1231E998AC77E72F661A0D5525A8AC3E078BCBCB0
E4726147566F21C09B654D0668D994D861CB134E5261D5E12584B887354896CD
E97F44C7915866C3127565A91373D03ADB639916186B24FC5E0F818A3BDE8D3F
45780D343AFA28884265003ECDE343700706B1BFCBC74B24F3F984E4EACE4E15
D82030E8689B19EFEDFBCE50CE38351CA81B302C06936584C6A27BDA18339DF8
05A3EA6FF8D8FA5CCA29D08F8D0BD67DAFD2CDFCB58A1293291F0EC654F70232
168E3C710448DBDD7E6FE2463B867339A72BE11A7C8615D72D19FB26572D3619
9F0EE5CEE06CAF2B020D2A1DCB6C346E5B6B98E6704BA6F165CC3CAA69BA7A70
C361F8A018CFFDAD1AD0A0CE3E5032FC7314DEC3F73642DC626A6121D487008B
1018C6BF8E39136E14A0637FF09410F34D696089953851F68869CE6C45D885F2
8EF78A37811529D73D37E29A9FA24BF2D46D0D5D97C4F6E403EA9ADEBC55EAF3
9EAA94C1C87F5671A04D4FF3F687BF2448CCAE06F1B7928BF0C6BA2AEC60E9B7
5EADBDEABDCA1A7ABF6416A6B35BF7AFD86E7EDADE7B5D44059FBCECACAEF372
264DB89E74213F3EA2D7B7379D1C2AC346797D03B4D88CBF4CE72C3FF96477A1
D0C53B1BFA741B7F6484200FAF8452E5A779357C2A29AA6B0DFDEDF7173E903F
62E12510B0097BD784B14B035013A32C65E7DA334220C3DDFCC90D87440D240C
420B09998AE215154B6665C4D8167A74FD99EB3D4D85D5657BA317666E65E301
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every Eclipse Temurin JDK with Hotspot 21 version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Matched on the categories Eclipse Adoptium and others declare in their own manifests, so the grouping is theirs rather than ours. Each one has its official URL and hash on the same terms as this page.
Not related to Eclipse Temurin JDK with Hotspot 21 — just other entries, each with its own official URL and published hash.