We suggest the following mirror site for your download:
Other mirror sites are suggested below. Please use the backup mirrors only to download PGP and MD5 signatures to verify your downloads or if no other mirrors are working.
Please use the backup mirrors only to download PGP and MD5 signatures to verify your downloads or if no other mirrors are working.
The full listing of mirror sites is also available.
Becoming a mirror
The procedure for setting up new mirrors is described in How to become a mirror.
Verify the integrity of the files
It is essential that you verify the integrity of the downloaded file using
the PGP signature (
.asc file) or a hash (
.sha file). Please read Verifying Apache Software
Foundation Releases for more information on why
you should verify our releases.
The PGP signature can be verified using PGP or GPG. First download the
KEYS as well as the
asc signature file for the relevant distribution.
Make sure you get these files from the main distribution site, rather than
from a mirror. Then verify the signatures using
% pgpk -a KEYS
% pgpv downloaded_file.asc
% pgp -ka KEYS or
% pgp downloaded_file.asc
% gpg --import
% gpg --verify downloaded_file.asc
Alternatively, you can verify the MD5 hash on the file. A unix
md5sum is included in many unix distributions. It
is also available as part of GNU
users can get binary md5 programs from here
, here , or