It is essential that you verify the integrity of the downloaded files using the PGP or MD5 signatures.
Please read Verifying Apache Software Foundation Releases for more information on why you should verify our releases.
The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the asc signature file for the relevant distribution.
Make sure you get these files from the main distribution site, rather than from a mirror.
Then verify the signatures using
% pgpk -a KEYS
% pgpv downloaded_file.asc
or
% pgp -ka KEYS
% pgp downloaded_file.asc
or
% gpg --import KEYS
% gpg --verify downloaded_file.asc
Alternatively, you can verify the MD5 signature on the files.
This is not very secure, and should only be used to check that the file has been downloaded successfully.
A unix program called md5 or md5sum is included in many unix distributions.
It is also available as part of
GNU Textutils
.
Windows users can get binary md5 programs from
here
,
here
, or
here
.