Re: Making www.cpan.org TLS-only
[email protected] ("David E. Wheeler") Fri, 1 Sep 2017 10:03:06 -0400
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <[email protected]> |
On Aug 31, 2017, at 9:10 PM, Ask Bjørn Hansen <[email protected]> wrote: > Hi everyone, > > We’re considering how/how-much we can make www.cpan.org TLS-only. > http://log.perl.org/2017/08/tls-only-for-wwwcpanorg.html > > I expect that we can’t make the whole site TLS-only without breaking some CPAN clients, so the conservative version is to force TLS for > > - any url ending in *.html > - any url not in matching some variation of > (/authors/ | /MIRRORED.BY | ^/modules/[^/]+ ) > > Does that sound about right? Maybe /src/, too? > > (Also - we will support TLS for www.cpan.org permanently now, so please update URLs where possible and appropriate). That file does not prevent someone from taking over the domain and modifying the files. Nor will it notice man-in-the-middle attacks. Without Any request without TLS has no proof of domain control. That, along with encryption, is the driving force behind the current “TLS for everything” movement. Best, David
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJZqWibAAoJEJLfYnT4yIHxb+MQAJbDvQDJaLoDfdct5Sg3SIP8 IQlpAP1usVna3llkiJr+FrUtcBBJnFszPsaY0kmoDHkauaJrIl6FP2zO520FZtwZ 4ET5omBGGYDdr3dgqdgA3/SGHbQNltVxtyKXJ1DOyzY/eLeMVaFohsWjcN1nNLmZ 5yUwg14QpluZVPYKFGxSAtFsFxkNQ7lIYGJrAxMu5TDLGj9TpcFgewMg0+yPCdMI xNVZSGTZGfr9ZaafIi5V5ODCQEHCSZig8OP/7SFnpMgmj/SvLTz2IPBeYXItULg3 xN25L/xDYVRdfHV9mui9TP+X6YiBq4IyBqJYngGhkFz2YDSHE+Sp3SBwtcd5ym7P +7o/DBhaDzT7FVUu1kYV9cTVsCeF891npkzUCTRP6B6zOEdDswD51YAMeS1w/GWn 4E1bPH61/cYlaBjYq4G0/vrMxLuwUPf+QUjzoeZJdGnvcZgU64rpVzDNpOE/FOd1 UOJD1XoyJwsP2+6z0yNLhLIa5x4jpTRO8vBLI1r6xx4KfxJFMblOHkZ3DWXlZ3lc i6cYjU0cvgqiK6Pvn7/QJ47WyE6EdZQLSp67CZ5+0azw81SaVOWjtUktY2w6v74D 6chB98OrIIle+AMycZGfY0EIsePqaMACD+RtEXhO10dSOno6I41mqO68w3Xdulfr AJLBLqt9SCkdM6D8mwCL =B6O9 -----END PGP SIGNATURE-----