From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mike Gerwitz Subject: bug#27437: Source downloader accepts X.509 certificate for incorrect domain Date: Thu, 22 Jun 2017 20:45:42 -0400 Message-ID: <87y3sj7cqx.fsf@gnu.org> References: <20170621061752.GA32412@jasmine.lan> <87lgolipi0.fsf@gnu.org> <87injohwac.fsf@netris.org> <20170622161108.GA15580@jasmine.lan> <87wp83rg4k.fsf@gnu.org> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:56211) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dOCkZ-0008ER-Df for bug-guix@gnu.org; Thu, 22 Jun 2017 20:47:04 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dOCkY-0004Th-Ep for bug-guix@gnu.org; Thu, 22 Jun 2017 20:47:03 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:59251) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dOCkY-0004Tb-Bd for bug-guix@gnu.org; Thu, 22 Jun 2017 20:47:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dOCkY-0006uZ-6F for bug-guix@gnu.org; Thu, 22 Jun 2017 20:47:02 -0400 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <87wp83rg4k.fsf@gnu.org> ("Ludovic \=\?utf-8\?Q\?Court\=C3\=A8s\=22'\?\= \=\?utf-8\?Q\?s\?\= message of "Thu, 22 Jun 2017 21:12:27 +0200") List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 27437@debbugs.gnu.org --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable On Thu, Jun 22, 2017 at 21:12:27 +0200, Ludovic Court=C3=A8s wrote: > I think only GNU and kernel.org provide signatures, which represents 6% > of our packages. Of the 30% that do not have an updater, surely some > have digital signatures, but we=E2=80=99re probably still below 10%. The > situation is bad in general=E2=80=A6 What about signed tags/commits? =2D-=20 Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: D6E9 B930 028A 6C38 F43B 2388 FEF6 3574 5E6F 6D05 https://mikegerwitz.com --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJZTGS2AAoJEIyRe39dxRuiQIgQAL8qV5TUQlz8XDnSwi3VxJxR /PC1SvNmOdhCvbeimSqDPf3VnP/jGGoMYy5mXXRRUEVkF11ILONYpUppI12bDWZc um+u7scyqnKiGF2Ri0c94TD/UFhRECc1+pV+k/JwsU8i/VZb146cvhq0+9qzlUY3 tKhw5+Il6k7Hy/89HUOXSHaR/Hek4Y9iLlAQ2YyK38UHBHkK0sGvlK+lB49Vv5wt jes8Ltr5h3NrVabphD0U/oIf60IypeG5DEhOUDqOq7UKuYYnXGHe3fqTaFC5G8gz aqnUxFqrfBlgjVOZmhIm4arX3cBxIIosOJgqD9dF9enoS9D5T0aTFf7ge48PdMP8 hJgghTQsJhxZvijimMNwqApXJPxZ4LuNdvKb/1Lz63kPLLMT9ROm7m4IZdy728sC 2qcoBMHEcmxFX9q5laYkSKNWGUkGmgiMZ5BlRYz6MPS17thPtU3Jy9vmPTeuQIs+ kCiko2hM98n065WR//RbBPvzMHBqHhPZv4fdcF2Qm7xP4WrkxdVvl4hW2gI2bsp7 Kxo6nAr4NRUZafYLubc9nAjn7AlkHiONkVMzA1s2Tjew8zV6C5Y7QhyueU1h8Q6T uAOIFjSXn4ndpyKdLyopXM9VLv1D/ecyW1gEDn67UzDMTOvpWEZZzGirkjcgrOby R5xPvMS/p1Pj06YN2ox+ =yl3f -----END PGP SIGNATURE----- --=-=-=--