These source archives are generated from tagged releases. Updates and patches will not have been applied. For any updates refer to the corresponding branches in the GitHub repository. Choose your flavor of download from the following links:

Version Source PGP SHA

## Verify the Integrity of the Files¶

It is essential that you verify the integrity of the downloaded file using the PGP signature (.asc file) or a hash (.md5 or .sha* file). Please read Verifying Apache Software Foundation Releases for more information on why you should verify our releases.

The PGP signature can be verified using PGP or GPG. First download the KEYS as well as the .asc signature file for the relevant distribution. Make sure you get these files from the main distribution site, rather than from a mirror. Then verify the signatures using one of the following alternatives:

% gpg --import KEYS

% pgpk -a KEYS

% pgp -ka KEYS


Alternatively, you can verify the hash on the file.

Hashes can be calculated using GPG:

% gpg --print-md SHA1 downloaded_file


The output should be compared with the contents of the SHA1 file. Similarly for other hashes (SHA256 MD5 etc) which may be provided.

Windows 7 and later systems should all now have certUtil:

% certUtil -hashfile pathToFileToCheck


HashAlgorithm choices: MD2 MD4 MD5 SHA1 SHA256 SHA384 SHA512

Unix-like systems (and macOS) will have a utility called md5, md5sum or shasum.