Do not download from www.apache.org. Please use a mirror site to help us save apache.org bandwidth. Go here to find your nearest mirror.
All of the release distribution packages have been digitally signed (using PGP or GPG) by the ASF committers that constructed them. There will be an accompanying distribution.asc file in the same directory as the distribution. The PGP/GPG keys can be found at the MIT key repository and within this project's KEYS file at http://www.apache.org/dist/commons/KEYS.
Always signatures to validate package authenticity, e.g., $ pgpk -a KEYS $ pgpv commons.tar.gz.asc or, $ pgp -ka KEYS $ pgp commons.tar.gz.asc or $ gpg --verify commons.tar.gz.asc
We also offer MD5 hashes as an alternative to validate the integrity of the downloaded files. See the distribution.md5 files.