On 11/20/2016 09:02 AM, Joerg Jaspert wrote:
> On 14496 March 1977, Luke wrote:
>
>> When navigating to https://ftp.debian.org it fails to load, due to 
>> improperly configured HTTPS.
>> Firefox gives - Error code: SEC_ERROR_UNKNOWN_ISSUER
>> Other subdomains of Debian do not have this problem. Providing HTTPS on this 
>> domain provides security from MITM attacks among other concerns.
> https does not help *anything* for the archive. MITM is no issue here.
>
> And ftpmaster does not run ftp.debian.org, wrong place.
>
In all respect, Debian is a cluster of confusion and no help. I
originally placed the bug against debian-www
(https://lists.debian.org/debian-www/2016/11/msg00033.html) and was told
that they are not in charge of it, and to file a bug here.

All I know is many downstream sources are actively using ftp.debian.org
to compile packages. They rarely check hash checks, cannot check GPG (as
it does not exist), and depend solely on HTTP as their method of
obtaining Debian sources and compiling for down stream. MiTM is a large
factor in this case, and is reproducibly easy to do.

Since you've closed this bug, where else can I go? Where is upstream?

Thank you.

- Luke


Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to