[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#27437: Source downloader accepts X.509 certificate for incorrect dom
From: |
Ludovic Courtès |
Subject: |
bug#27437: Source downloader accepts X.509 certificate for incorrect domain |
Date: |
Fri, 23 Jun 2017 11:31:40 +0200 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/25.2 (gnu/linux) |
Mike Gerwitz <address@hidden> skribis:
> On Thu, Jun 22, 2017 at 21:12:27 +0200, Ludovic Courtès wrote:
>> I think only GNU and kernel.org provide signatures, which represents 6%
>> of our packages. Of the 30% that do not have an updater, surely some
>> have digital signatures, but we’re probably still below 10%. The
>> situation is bad in general…
>
> What about signed tags/commits?
They’re becoming more widespread, especially now that GitHub’s UI can
make sense of them. Nevertheless, I don’t think it changes the ratio
much if we look at the whole package set that we have.
Ludo’.
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, Leo Famulari, 2017/06/21
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, ng0, 2017/06/22
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, Ricardo Wurmus, 2017/06/22
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, Marius Bakke, 2017/06/22
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, Leo Famulari, 2017/06/22
- bug#27437: Source downloader accepts X.509 certificate for incorrect domain, Ricardo Wurmus, 2017/06/23