IIUC the most important, and quite easy, thing they could be done here
before we can also have the right thing on server side is for Oliver to
publish the hash for the local file he uploaded?

This way even if someone was able to midm the http:// server folks could
check they're testing the expected binaries?

WDYT ?

Oliver, are you able to add the computed hash in this thread?

Thanks

-- Baptiste

Le mar. 11 août 2020 à 17:24, Mark Waite <mark.earl.wa...@gmail.com> a
écrit :

>
> On Tue, Aug 11, 2020 at 8:55 AM 'Björn Pedersen' via Jenkins Developers <
> jenkinsci-dev@googlegroups.com> wrote:
>
>> It looks like the certificate does not  cover all domains that  are
>> currently server:
>>
>> This server could not prove that it is mirrors.jenkins-ci.org; its
>> security certificate is from pkg.origin.jenkins.io. This may be caused
>> by a misconfiguration or an attacker intercepting your connection
>> As it is a letsencyrpt certifacte, maybe just adding the domain (
>> https://certbot.eff.org/docs/using.html#changing-a-certificate-s-domains
>> if using certbot)  could help?
>>
>>
>   Unfortunately, there's significantly more involved in the transition
> than adding an SSL certificate to the domain.
>
> That location is the root of the Jenkins mirrors.  The mirroring software
> we use does not support HTTPS.  We're in the process of switching to new
> mirroring software that supports HTTPS.
>
>
>> Björn
>> johno.c...@gmail.com schrieb am Montag, 10. August 2020 um 19:33:23
>> UTC+2:
>>
>>> Would be great if in the future you could provide a https link and
>>> hashes of the binary. Sadly I did a little bit of digging and found this
>>> ticket.. https://issues.jenkins.io/browse/INFRA-266
>>>
>>> J
>>>
>>> On Mon, Aug 10, 2020 at 7:25 PM Johno Crawford <johno.c...@gmail.com>
>>> wrote:
>>>
>>>> Hi Oliver,
>>>>
>>>> Any https servers available to download the latest LTS RC?
>>>>
>>>> J
>>>>
>>>> On Sun, Aug 2, 2020 at 9:30 AM Oliver Gondža <ogo...@gmail.com> wrote:
>>>>
>>>>> Hello everyone,
>>>>>
>>>>> Latest LTS RC was made public and it is ready to be tested. Final
>>>>> release is scheduled for 2020-08-12.
>>>>>
>>>>> Please, report your findings in this thread.
>>>>>
>>>>> Download bits from
>>>>> http://mirrors.jenkins-ci.org/war-stable-rc/2.235.4/jenkins.war
>>>>>
>>>>> Thanks!
>>>>> --
>>>>> oliver
>>>>>
>>>>> --
>>>>> You received this message because you are subscribed to the Google
>>>>> Groups "Jenkins Developers" group.
>>>>> To unsubscribe from this group and stop receiving emails from it, send
>>>>> an email to jenkinsci-de...@googlegroups.com.
>>>>> To view this discussion on the web visit
>>>>> https://groups.google.com/d/msgid/jenkinsci-dev/84782d44-dd40-619f-9f6f-2585455bc89d%40gmail.com
>>>>> .
>>>>>
>>>>
>>>>
>>>> --
>>>> Johno Crawford
>>>>
>>>
>>>
>>> --
>>> Johno Crawford
>>>
>> --
>> You received this message because you are subscribed to the Google Groups
>> "Jenkins Developers" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to jenkinsci-dev+unsubscr...@googlegroups.com.
>> To view this discussion on the web visit
>> https://groups.google.com/d/msgid/jenkinsci-dev/c632c50b-fe72-4f4e-84fb-1f2e47c26901n%40googlegroups.com
>> <https://groups.google.com/d/msgid/jenkinsci-dev/c632c50b-fe72-4f4e-84fb-1f2e47c26901n%40googlegroups.com?utm_medium=email&utm_source=footer>
>> .
>>
> --
> You received this message because you are subscribed to the Google Groups
> "Jenkins Developers" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to jenkinsci-dev+unsubscr...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/jenkinsci-dev/CAO49JtGs4EO1gAk_P%3DVXkytxrmzzq7AkqSewrKr4yTd22k_rRw%40mail.gmail.com
> <https://groups.google.com/d/msgid/jenkinsci-dev/CAO49JtGs4EO1gAk_P%3DVXkytxrmzzq7AkqSewrKr4yTd22k_rRw%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>

-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to jenkinsci-dev+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/jenkinsci-dev/CANWgJS45HWB7uSQU04B_3FdxvDzVNyLShv_727gtCCpj56QvPg%40mail.gmail.com.

Reply via email to