<h2><a name="mirrors">Download from your
<a href="">nearest mirror site!</a></a></h2>

Do not download from Please use a mirror site
to help us save bandwidth.
<a href="">Go here to find your nearest mirror.</a>

<h2><a name="sig">PGP/GPG Signatures</a></h2>

All of the release distribution packages have been digitally
signed (using PGP or GPG) by the ASF committers that constructed
them. There will be an accompanying
<tt><var>distribution</var>.asc</tt> file in the same directory
as the distribution. The PGP/GPG keys can be found at the MIT key
repository and within this project's KEYS file at
<a href=""><samp></samp></a>.

<h4>Always download the KEYS file directly from the Apache site, never from a mirror.</h4>

<pre>Always check signatures to validate package authenticity, <i>e.g.</i>,
$ pgpk -a KEYS
$ pgpv apache-jmeter-5.6.3.tgz.asc
$ pgp -ka KEYS
$ pgp apache-jmeter-5.6.3.tgz.asc
$ gpg --verify apache-jmeter-5.6.3.tgz.asc apache-jmeter-5.6.3.tgz

We also offer SHA512 hashes to validate the
integrity of the downloaded files. See the
<tt><var>distribution</var>.sha512</tt> files.
Note that such hashes are only useful as a check that the file has been downloaded OK.
They do not provide any guarantee that the downloaded file is authentic.