Re: HTTPS metadata in Mirrors.masterlist?

Axel Beckert <[email protected]>
Newsgroups gmane.linux.debian.user.mirrors
Organization The Debian Project
Message-ID <[email protected]>
Hi,

Bastian Blank wrote:
> On Sun, Apr 09, 2017 at 12:07:33PM +0200, Axel Beckert wrote:
> > Peter Palfrader wrote:
> > > Adding https just makes this a whole extra mess.
> > As outlined in my recent mail I don't think that it's that much of an
> > extra-effort once we track HTTPS in Mirrors.masterlist. And I
> > especially think the gain outweighs the additional effort.
> 
> Please describe a workflow that allows us to re-point ftp.*.debian.org at
> will without intervention of the admin of the real system.

IIRC I outlined this before: A wild card certificate for
ftp.*.debian.org (or ftp*.*.debian.org as there are hostnames like
ftp2.de.debian.org out there) on those DSA-controlled machines like
kassia which work as temporary replacement.

> No, Let's Encrypt does not help, as this only allows to add live
> hostnames to certificates.

I'm fully aware of that. But as Mattias Wadenstein already outline,
there's also a slightly bumpy way to do that if you really want to use
LE for that. I'd prefer a wild card certificate.

		Regards, Axel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.