When downloading from a mirror please check the MD5 and SHA checksums as well as verifying the OpenPGP compatible signature available from the main Apache site. The KEYS file contains the public keys used for signing release. It is recommended that a web of trust is used to confirm the identity of these keys.
You can check the OpenPGP signature with:
gpg --verify apache-couchdb-*.tar.gz.asc
You can check the MD5 checksum with:
md5sum --check apache-couchdb-*.tar.gz.md5
You can check the SHA checksum with:
sha1sum --check apache-couchdb-*.tar.gz.sha