Re: rt.cpan.org uses an invalid security certificate.
[email protected] ("Mark J. Reed") Thu, 18 Sep 2008 11:37:22 -0400
| Newsgroups | perl.cpan.discuss |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Sep 18, 2008 at 11:09 AM, Marc Girod <[email protected]> wrote: > This is recent, isn't it? > I must have been able to sign in already in the past... > Maybe not more recently than a bit less than one year ago. The change is Firefox 3, which is much pickier about such things than Firefox 2. > P.S. Shouldn't this be a FAQ? Probably. > Or would that be a security hole? The fact that the cert is self-signed is a security hole, since it potentially allows traffic to be intercepted by a third party; but writing up a FAQ entry on it wouldn't make the hole any bigger. So what would it take to get a real cert going? It looks like a minimally-verified (proven ownership of the domain name) SSL cert is about $50/year. I know this came up in another thread recently, but I didn't see an ansewr: who foots the bill for CPAN's domain registration? -- Mark J. Reed <[email protected]>