From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?UTF-8?Q?Court=C3=A8s?=) Subject: bug#27437: Source downloader accepts X.509 certificate for incorrect domain Date: Fri, 23 Jun 2017 11:31:40 +0200 Message-ID: <87podvaw3n.fsf@gnu.org> References: <20170621061752.GA32412@jasmine.lan> <87lgolipi0.fsf@gnu.org> <87injohwac.fsf@netris.org> <20170622161108.GA15580@jasmine.lan> <87wp83rg4k.fsf@gnu.org> <87y3sj7cqx.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:47121) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dOKwg-0001Au-SO for bug-guix@gnu.org; Fri, 23 Jun 2017 05:32:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dOKwb-0001mt-Sn for bug-guix@gnu.org; Fri, 23 Jun 2017 05:32:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:59430) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dOKwb-0001mp-PH for bug-guix@gnu.org; Fri, 23 Jun 2017 05:32:01 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dOKwb-0002Do-K1 for bug-guix@gnu.org; Fri, 23 Jun 2017 05:32:01 -0400 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <87y3sj7cqx.fsf@gnu.org> (Mike Gerwitz's message of "Thu, 22 Jun 2017 20:45:42 -0400") List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Mike Gerwitz Cc: 27437@debbugs.gnu.org Mike Gerwitz skribis: > On Thu, Jun 22, 2017 at 21:12:27 +0200, Ludovic Court=C3=A8s wrote: >> I think only GNU and kernel.org provide signatures, which represents 6% >> of our packages. Of the 30% that do not have an updater, surely some >> have digital signatures, but we=E2=80=99re probably still below 10%. The >> situation is bad in general=E2=80=A6 > > What about signed tags/commits? They=E2=80=99re becoming more widespread, especially now that GitHub=E2=80= =99s UI can make sense of them. Nevertheless, I don=E2=80=99t think it changes the rat= io much if we look at the whole package set that we have. Ludo=E2=80=99.