The Apache Santuario™ project is aimed at providing implementation of the primary security standards for XML. Two libraries are currently available.
Use the links below to download a distribution of Apache Santuario from one of our mirrors. It is good practice to verify the integrity of the distribution files. Apache Santuario releases are available under the Apache License, Version 2.0 - see the LICENSE.txt and NOTICE.txt files contained in each release artifact.
Older releases are available in the archive.
It is essential that you verify the integrity of the downloaded files using the PGP signatures. Digest verification ensures the file was not corrupted or tampered with but provides no real verification of authenticity. PGP verification ensures that the file is authentic. In practice, PGP verification is much more important and makes checksum verification redundant.
The PGP signatures can be verified using PGP or GPG. First download the Apache Santuario KEYS as well as the *.asc signature file for the particular distribution. It is important that you get these files from the ultimate trusted source - the main ASF distribution site, rather than from a mirror. Then verify the signatures using:
To verify the SHA checksum on the files, you need to use a program called sha1sum (or sha256sum, etc.), which is included in many unix distributions. It is also available as part of GNU Textutils. Windows users can get binary digest programs from here or an openssl client from here.
We strongly recommend you verify your downloads with PGP.