Verifying the integrity of the files

It is essential that you verify the integrity of the downloaded files using the PGP or MD5 signatures. Security of the mirrors cannot be guaranteed, which means malicious code could be added to the downloads from the mirrors. By verifying the integrity of downloaded release files, you ensure they have not been tainted.

Run the following command to verify the MD5 sum. It should give output similar to "apache-VCL-2.4.2.tar.bz2: OK":

md5sum -c apache-VCL-2.4.2.tar.bz2.md5

Similarly, run the following command to verify the SHA1 sum. You should get output similar to "apache-VCL-2.4.2.tar.bz2: OK":

sha1sum -c apache-VCL-2.4.2.tar.bz2.sha1

To verify the GPG signature (you'll need to have GnuPG installed):

  1. download and import the VCL KEYS file (if you've imported the KEYS file for previously releases, you do not need to import it again):

    gpg --import KEYS
  2. download the GPG Signature to the same location as the release file

  3. from the directory containing both the release file and the GPG signature, run

    gpg --verify apache-VCL-2.4.2.tar.bz2.asc


For new installs, visit the on-line installation guide:

Latest Version:

Previous Versions:


For upgrades, visit the on-line upgrade guide:

Upgrade to latest version:

Upgrade to 2.3.2

Upgrade to 2.2.2:

Upgrade really old versions to older versions:

to 2.3.1

to 2.3

to 2.2.1

to 2.2

Release Notes

See the release notes page for information about each release.

Change Log

See the change log page for changes made in each release.