Verifying the download package

Verify the integrity of downloaded HCL Commerce packages by using SHA values to ensure the files are complete, uncorrupted, and unmodified.

Before you begin

To generate a hash signature, you must identify and obtain an SHA hash utility. Most UNIX and Linux operating systems include utilities to generate an SHA hash. Microsoft Windows does not include an SHA utility, but many third-party options are available.

About this task

The following steps provide high-level instructions to verify the download package:

Procedure

  1. Use your SHA hash utility to generate a hash signature of your copy of the package.
  2. Compare the generated signature hash with the HCL SHA value. Ensure that the values are identical.
    To confirm SHA values, you can obtain a copy from HCL in one of two ways:
    1. Viewing the file properties on the My HCLSoftware portal. You can view the file SHA value by clicking on the + icon in the + column, to the left of the file description.
    2. Viewing a copy of its SHA value on the HCL Commerce eAssemblies (downloads) documentation page.

Results

If the values are identical, then proceed to install or use the package. If the values are not identical, then the package might be corrupted. Try to download the package from the trusted HCL source and verify the values. If the values do not match, then contact HCL Support.