 
     
    
The requested file or directory is not on the mirrors.
The object is in our archive : https://archive.apache.org/dist/cxf/2.3.7/apache-cxf-2.3.7-src.tar.gz
    It is essential that you verify the integrity of the downloaded file using
    the PGP signature (
    .asc
     file) or a hash (
    .md5
     or 
    .sha*
     file). Please read 
    Verifying Apache Software
    Foundation Releases
     for more information on why
    you should verify our releases.
    The PGP signature can be verified using PGP or GPG. First download the
    KEYS
     as well as the 
    asc
     signature file for the relevant distribution.
    Make sure you get these files from the main distribution site, rather than
    from a mirror. Then verify the signatures using
        % gpg --import KEYS
        % gpg --verify downloaded_file.asc downloaded_file
    
or
        % pgpk -a KEYS
        % pgpv downloaded_file.asc
    
or
        % pgp -ka KEYS
        % pgp downloaded_file.asc
    
    Alternatively, you can verify the MD5 hash on the file. A unix
    program called 
    md5
     or 
    md5sum
     is included in many unix distributions. It
    is also available as part of 
    GNU Textutils
    .
    Windows users can get binary md5 programs from
    here
    , 
    here
     , or
    here
    .