We suggest the following site for your download:
Alternate download locations are suggested below.
It is essential that you verify the integrity of the downloaded file using
the PGP signature (.asc
file) or a hash (.md5
or .sha*
file).
It is essential that you verify the integrity of the downloaded file using
the PGP signature (.asc
file) or a hash (.md5
or .sha*
file). Please read Verifying Apache Software
Foundation Releases for more information on why
you should verify our releases.
Verify the PGP signature using PGP or GPG. First download the
KEYS
as well as the asc
signature file for the relevant distribution.
% gpg --import KEYS % gpg --verify downloaded_file.asc downloaded_file
or
% pgpk -a KEYS % pgpv downloaded_file.asc
or
% pgp -ka KEYS % pgp downloaded_file.asc
Alternatively, you can verify the hash on the file.
Hashes can be calculated using GPG:
% gpg --print-md SHA256 downloaded_file
Compare the output with the contents of the SHA256 file. Similarly for other hashes (SHA512, SHA1, MD5 etc) which may be provided.
Windows 7 and later systems should all now have certUtil:
% certUtil -hashfile pathToFileToCheck
HashAlgorithm choices: MD2 MD4 MD5 SHA1 SHA256 SHA384 SHA512
Unix-like systems (and macOS) will have a utility called md5, md5sum or shasum