Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-08 Thread Petr Pisar
On Sat, Jul 07, 2012 at 01:25:49PM -0600, Daniel Kahn Gillmor wrote: > On 07/07/2012 12:50 PM, Ángel González wrote: > > On 06/07/12 01:01, pro...@secure-mail.biz wrote: > >> Because SSL CA's have failed many times (Comodo, DigiNotar, ...) I wish to > >> have an option to pin a SSL certificate. Th

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread Daniel Kahn Gillmor
On 07/07/2012 02:20 PM, Dagobert Michelsen wrote: > I have a tiny comment from a downstream packager standpoint: It would be nice > if the > capath would be configurable during configure time instead of hardcoding it > to /etc/ssl/certs as it is now - we e.g. use /etc/opt/csw/ssl/certs and need >

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread Dagobert Michelsen
Hi, I have a tiny comment from a downstream packager standpoint: It would be nice if the capath would be configurable during configure time instead of hardcoding it to /etc/ssl/certs as it is now - we e.g. use /etc/opt/csw/ssl/certs and need to perl-pi in the unpacked sources. Not a real problem,

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread Ángel González
On 07/07/12 21:25, Daniel Kahn Gillmor wrote: > On 07/07/2012 12:50 PM, Ángel González wrote: >> On 06/07/12 01:01, pro...@secure-mail.biz wrote: >>> Because SSL CA's have failed many times (Comodo, DigiNotar, ...) I wish to >>> have an option to pin a SSL certificate. The fingerprint may be optio

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread proper
wrote: > On 07/07/2012 12:50 PM, Ángel González wrote: > > On 06/07/12 01:01, pro...@secure-mail.biz wrote: > >> Because SSL CA's have failed many times (Comodo, DigiNotar, ...) > I wish to have an option to pin a SSL certificate. The fingerprint may be > optionally provided through a new option.

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread Daniel Kahn Gillmor
On 07/07/2012 12:50 PM, Ángel González wrote: > On 06/07/12 01:01, pro...@secure-mail.biz wrote: >> Because SSL CA's have failed many times (Comodo, DigiNotar, ...) I wish to >> have an option to pin a SSL certificate. The fingerprint may be optionally >> provided through a new option. > Have you

Re: [Bug-wget] [FEATURE-REQUEST] Pinning SSL certificates / check SSL fingerprints

2012-07-07 Thread Ángel González
On 06/07/12 01:01, pro...@secure-mail.biz wrote: > Because SSL CA's have failed many times (Comodo, DigiNotar, ...) I wish to > have an option to pin a SSL certificate. The fingerprint may be optionally > provided through a new option. Have you tried using --ca-certificate option?