Re: Making www.cpan.org TLS-only

[email protected] ("David E. Wheeler") Fri, 1 Sep 2017 10:03:06 -0400
Newsgroups perl.cpan.workers
Message-ID <[email protected]>
On Aug 31, 2017, at 9:10 PM, Ask Bjørn Hansen <[email protected]> wrote:

> Hi everyone,
> 
> We’re considering how/how-much we can make www.cpan.org TLS-only.
> http://log.perl.org/2017/08/tls-only-for-wwwcpanorg.html
> 
> I expect that we can’t make the whole site TLS-only without breaking some CPAN clients, so the conservative version is to force TLS for
> 
> - any url ending in *.html
> - any url not in matching some variation of
>     (/authors/ | /MIRRORED.BY | ^/modules/[^/]+ )
> 
> Does that sound about right? Maybe /src/, too?
> 
> (Also - we will support TLS for www.cpan.org permanently now, so please update URLs where possible and appropriate).

That file does not prevent someone from taking over the domain and modifying the files. Nor will it notice man-in-the-middle attacks. Without Any request without TLS has no proof of domain control. That, along with encryption, is the driving force behind the current “TLS for everything” movement.

Best,

David
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJZqWibAAoJEJLfYnT4yIHxb+MQAJbDvQDJaLoDfdct5Sg3SIP8
IQlpAP1usVna3llkiJr+FrUtcBBJnFszPsaY0kmoDHkauaJrIl6FP2zO520FZtwZ
4ET5omBGGYDdr3dgqdgA3/SGHbQNltVxtyKXJ1DOyzY/eLeMVaFohsWjcN1nNLmZ
5yUwg14QpluZVPYKFGxSAtFsFxkNQ7lIYGJrAxMu5TDLGj9TpcFgewMg0+yPCdMI
xNVZSGTZGfr9ZaafIi5V5ODCQEHCSZig8OP/7SFnpMgmj/SvLTz2IPBeYXItULg3
xN25L/xDYVRdfHV9mui9TP+X6YiBq4IyBqJYngGhkFz2YDSHE+Sp3SBwtcd5ym7P
+7o/DBhaDzT7FVUu1kYV9cTVsCeF891npkzUCTRP6B6zOEdDswD51YAMeS1w/GWn
4E1bPH61/cYlaBjYq4G0/vrMxLuwUPf+QUjzoeZJdGnvcZgU64rpVzDNpOE/FOd1
UOJD1XoyJwsP2+6z0yNLhLIa5x4jpTRO8vBLI1r6xx4KfxJFMblOHkZ3DWXlZ3lc
i6cYjU0cvgqiK6Pvn7/QJ47WyE6EdZQLSp67CZ5+0azw81SaVOWjtUktY2w6v74D
6chB98OrIIle+AMycZGfY0EIsePqaMACD+RtEXhO10dSOno6I41mqO68w3Xdulfr
AJLBLqt9SCkdM6D8mwCL
=B6O9
-----END PGP SIGNATURE-----