Verify the integrity of the files
It is essential that you verify the integrity of the downloaded files using the PGP or MD5 signatures.
The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the
PGP signature file for the relevant file. Make sure you get these files from the main distribution directory,
rather than from a mirror. Then verify the signatures using, for instance:
% gpg --import KEYS
% gpg --verify unomi-2.4.0-bin.tar.gz.asc unomi-2.4.0-bin.tar.gz