We suggest the following mirror site for your download:
Download jar and war files
- the ASC file (OpenPGP compatible signature) with the KEYS file (code signing keys used to sign the product)
- the MD5 file (checksum).
The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the asc signature file for the relevant distribution. Then verify the signatures using:
$ pgpk -a KEYS $ pgpv fortress-core-2.0.0-RC2.jar.asc
$ pgp -ka KEYS $ pgp fortress-core-2.0.0-RC2.jar.asc
$ gpg --import KEYS $ gpg --verify fortress-core-2.0.0-RC2.jar.asc
Alternatively, you can verify the MD5 signature on the files. A unix program called md5 or md5sum is included in many unix distributions. It is also available as part of GNU Textutils. Windows users can get binary md5 programs from here, here, or here.