Re: there seems a better download location for popt

"Xi Ruoyao" ([email protected] via blfs-dev Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel
Message-ID <[email protected]>
On Sat, 2024-11-23 at 19:23 +0800, Zhang Wen wrote:
> I'm trying to download every package with https protocal, and find
> that 
> the ssl certificate used by ftp.rpm.org is only valid for osuosl.org.
> The file downloaded from 
> https://ftp.osuosl.org/pub/rpm/popt/releases/popt-1.x/popt-1.19.tar.gz
>  
> and http://ftp.rpm.org/popt/releases/popt-1.x/popt-1.19.tar.gz has the
> same md5 values.
> IMO using https over http is always meaningful, and JFYI archlinux is 
> also using the osuosl location.

As the upstream website https://rpm.org/download.html suggests to use
https://ftp.osuosl.org, let's just use it.  I've just pushed the change
(with some other http -> https changes).

But in general using https over http is NOT always meaningful.  If we
engaged a crusader march against http we'd just replace every http://
URLs with a URL to https://ftp2.osuosl.org/pub/blfs/conglomeration/, but
then we'd be no longer tracking the upstream.

And for mc we have
https://midnight-commander.org/downloads/mc-4.8.32.tar.xz, but it just
redirects to the insecure
http://ftp.midnight-commander.org/mc-4.8.32.tar.xz so switching to the
https URL here would be just a meaningless self-comforting.

After my changes there are 9 packages remaining with a http:// download
URL:

rxvt-unicode
fcron
pax (wget dislikes the old TLS 1.0 protocol of https://www.mirbsd.org/)
mc
libptytty
highlight
dash
links
libndp

-- 
Xi Ruoyao <[email protected]>
School of Aerospace Science and Technology, Xidian University

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.