Re: security-tracker now on https?

2013-05-24 Thread Martin Zobel-Helas
Hi, On Fri May 24, 2013 at 21:42:27 +0200, Florian Weimer wrote: > * Martin Zobel-Helas: > > >> No, wildcards certificates are generally only licensed for > >> installation on a single server. > > > > http://www.digicert.com/wildcard-ssl-certificates.htm > > > > "And every DigiCert wildcard cert

Re: security-tracker now on https?

2013-05-24 Thread Florian Weimer
* Martin Zobel-Helas: >> No, wildcards certificates are generally only licensed for >> installation on a single server. > > http://www.digicert.com/wildcard-ssl-certificates.htm > > "And every DigiCert wildcard certificate comes with an unlimited server > license, so you only pay once—whether you

Re: security-tracker now on https?

2013-05-24 Thread Martin Zobel-Helas
Hi, On Fri May 24, 2013 at 20:09:57 +0200, Florian Weimer wrote: > * Stephen Gran: > > > This one time, at band camp, Florian Weimer said: > >> * Peter Palfrader: > >> > >> > The "solution" I'm favouring right now is to get a single *.debian.org > >> > wildcard from the cartell and spread it fa

Re: security-tracker now on https?

2013-05-24 Thread Florian Weimer
* Stephen Gran: > This one time, at band camp, Florian Weimer said: >> * Peter Palfrader: >> >> > The "solution" I'm favouring right now is to get a single *.debian.org >> > wildcard from the cartell and spread it far and wide. >> >> The contract terms usually do not allow this. >> >> We could

Re: security-tracker now on https?

2013-05-21 Thread Stephen Gran
Hi, This one time, at band camp, Florian Weimer said: > * Peter Palfrader: > > > The "solution" I'm favouring right now is to get a single *.debian.org > > wildcard from the cartell and spread it far and wide. > > The contract terms usually do not allow this. > > We could ask StartSSL or some o

Re: security-tracker now on https?

2013-05-19 Thread Florian Weimer
* Peter Palfrader: > The "solution" I'm favouring right now is to get a single *.debian.org > wildcard from the cartell and spread it far and wide. The contract terms usually do not allow this. We could ask StartSSL or some other CA if they would issue certificates to us in a convenient way. -

Re: security-tracker now on https?

2013-05-17 Thread Henri Salo
On Fri, May 17, 2013 at 10:58:33AM +0200, Thijs Kinkhorst wrote: > But for the security-tracker case, is there a need to be redirecting to > HTTPS at all? All information there is already public and no logins > happen. I do not think we need HTTPS to that site as is. --- Henri Salo -- To UNSUB

Re: security-tracker now on https?

2013-05-17 Thread Peter Palfrader
On Fri, 17 May 2013, Thijs Kinkhorst wrote: > Hi dsa, > > On Thu, April 4, 2013 11:10, Thijs Kinkhorst wrote: > > Hi admins, > > > > It was noted that the security tracker now blanket redirects to > > https://security-tracker.debian.org. This is fine of course for us DD's, > > but it presents a p

Re: security-tracker now on https?

2013-05-17 Thread Thijs Kinkhorst
On Fri, May 17, 2013 10:50, Peter Palfrader wrote: > On Fri, 17 May 2013, Thijs Kinkhorst wrote: > >> Hi dsa, >> >> On Thu, April 4, 2013 11:10, Thijs Kinkhorst wrote: >> > Hi admins, >> > >> > It was noted that the security tracker now blanket redirects to >> > https://security-tracker.debian.org.

Re: security-tracker now on https?

2013-05-17 Thread Thijs Kinkhorst
Hi dsa, On Thu, April 4, 2013 11:10, Thijs Kinkhorst wrote: > Hi admins, > > It was noted that the security tracker now blanket redirects to > https://security-tracker.debian.org. This is fine of course for us DD's, > but it presents a problem for externals using it. The tracker is often > used by

security-tracker now on https?

2013-04-04 Thread Thijs Kinkhorst
Hi admins, It was noted that the security tracker now blanket redirects to https://security-tracker.debian.org. This is fine of course for us DD's, but it presents a problem for externals using it. The tracker is often used by e.g. different distributions like RH and Gentoo, which may not have the