Re: HTTPS metadata in Mirrors.masterlist?
Axel Beckert <[email protected]>
| Newsgroups | gmane.linux.debian.user.mirrors |
|---|---|
| Organization | The Debian Project |
| Message-ID | <[email protected]> |
Hi, Bastian Blank wrote: > On Sun, Apr 09, 2017 at 12:07:33PM +0200, Axel Beckert wrote: > > Peter Palfrader wrote: > > > Adding https just makes this a whole extra mess. > > As outlined in my recent mail I don't think that it's that much of an > > extra-effort once we track HTTPS in Mirrors.masterlist. And I > > especially think the gain outweighs the additional effort. > > Please describe a workflow that allows us to re-point ftp.*.debian.org at > will without intervention of the admin of the real system. IIRC I outlined this before: A wild card certificate for ftp.*.debian.org (or ftp*.*.debian.org as there are hostnames like ftp2.de.debian.org out there) on those DSA-controlled machines like kassia which work as temporary replacement. > No, Let's Encrypt does not help, as this only allows to add live > hostnames to certificates. I'm fully aware of that. But as Mattias Wadenstein already outline, there's also a slightly bumpy way to do that if you really want to use LE for that. I'd prefer a wild card certificate. Regards, Axel