Re: there seems a better download location for popt
| Newsgroups | gmane.linux.lfs.beyond.devel |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 2024-11-23 at 19:23 +0800, Zhang Wen wrote: > I'm trying to download every package with https protocal, and find > that > the ssl certificate used by ftp.rpm.org is only valid for osuosl.org. > The file downloaded from > https://ftp.osuosl.org/pub/rpm/popt/releases/popt-1.x/popt-1.19.tar.gz > > and http://ftp.rpm.org/popt/releases/popt-1.x/popt-1.19.tar.gz has the > same md5 values. > IMO using https over http is always meaningful, and JFYI archlinux is > also using the osuosl location. As the upstream website https://rpm.org/download.html suggests to use https://ftp.osuosl.org, let's just use it. I've just pushed the change (with some other http -> https changes). But in general using https over http is NOT always meaningful. If we engaged a crusader march against http we'd just replace every http:// URLs with a URL to https://ftp2.osuosl.org/pub/blfs/conglomeration/, but then we'd be no longer tracking the upstream. And for mc we have https://midnight-commander.org/downloads/mc-4.8.32.tar.xz, but it just redirects to the insecure http://ftp.midnight-commander.org/mc-4.8.32.tar.xz so switching to the https URL here would be just a meaningless self-comforting. After my changes there are 9 packages remaining with a http:// download URL: rxvt-unicode fcron pax (wget dislikes the old TLS 1.0 protocol of https://www.mirbsd.org/) mc libptytty highlight dash links libndp -- Xi Ruoyao <[email protected]> School of Aerospace Science and Technology, Xidian University -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page