On Mon, Oct 20, 2014 at 4:10 AM, Gregory Szorc <[email protected]> wrote:
> "b" is a somewhat gnarly-looking Perl script that downloads certdata.txt
> from http://hg.mozilla.org/ or http://mxr.mozilla.org/ (more non-HTTPS
> URLS!) (hostname depends on which version / instruction you are looking at),
> and somehow munges it into a PEM file.

These servers are also available over TLS. I filed
https://bugzilla.mozilla.org/show_bug.cgi?id=1077394 a while ago to
restrict them to TLS.


-- 
https://annevankesteren.nl/
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to