Re: HTTPS for mirrors

2022-05-01 Thread Giovanni Bechis
ther is https?  Then we can ask mirrors to start >> moving to https with a goal perhaps of next May? >> >> Regards, >> >> KAM >> >> On 4/29/2022 12:27 AM, Dave Warren wrote: >>> On 2022-04-28 07:30, Bill Cole wrote: >>>> I see no reason to

Re: HTTPS for mirrors

2022-04-30 Thread Kevin A. McGrail
rren wrote: On 2022-04-28 07:30, Bill Cole wrote: I see no reason to make HTTPS mandatory for mirrors at this point. It does mean an extra layer that can break and the impersonation attacks that it enables would be extremely complicated to mount, so may be entirely theoretical. I would rather keep u

Re: HTTPS for mirrors

2022-04-30 Thread Henrik K
her is https?  Then we can ask mirrors to start > moving to https with a goal perhaps of next May? > > Regards, > > KAM > > On 4/29/2022 12:27 AM, Dave Warren wrote: > > On 2022-04-28 07:30, Bill Cole wrote: > > > I see no reason to make HTTPS mandatory fo

Re: HTTPS for mirrors

2022-04-30 Thread Kevin A. McGrail
wrote: On 2022-04-28 07:30, Bill Cole wrote: I see no reason to make HTTPS mandatory for mirrors at this point. It does mean an extra layer that can break and the impersonation attacks that it enables would be extremely complicated to mount, so may be entirely theoretical. I would rather keep

Re: HTTPS for mirrors

2022-04-28 Thread Dave Warren
On 2022-04-28 07:30, Bill Cole wrote: I see no reason to make HTTPS mandatory for mirrors at this point. It does mean an extra layer that can break and the impersonation attacks that it enables would be extremely complicated to mount, so may be entirely theoretical. I would rather keep

Re: HTTPS for mirrors

2022-04-28 Thread Henrik K
On Wed, Apr 27, 2022 at 05:34:57PM +0300, Henrik K wrote: > > Btw I just updated DNS to https too: > mirrors.updates.spamassassin.org. > "https://spamassassin.apache.org/updates/MIRRORED.BY; Actually it's now: mirrors.updates.spamassassin.org.

Re: HTTPS for mirrors

2022-04-28 Thread Henrik K
On Thu, Apr 28, 2022 at 09:30:21AM -0400, Bill Cole wrote: > > and the impersonation attacks that it enables would be extremely > complicated to mount, so may be entirely theoretical. Of course it is. It's probably thousand times more likely that a mirror itself is hacked and it's files

Re: HTTPS for mirrors

2022-04-28 Thread Bill Cole
On 2022-04-28 at 06:40:58 UTC-0400 (Thu, 28 Apr 2022 12:40:58 +0200 (CEST)) Fossies Administrator is rumored to have said: On Wed, 27 Apr 2022, Henrik K wrote: There's really no reason these days for not using https. Only three mirrors work with it right now: sa-update.razx.cloud sa

Re: HTTPS for mirrors

2022-04-28 Thread Bill Cole
On 2022-04-28 at 07:36:45 UTC-0400 (Thu, 28 Apr 2022 14:36:45 +0300) Henrik K is rumored to have said: On Thu, Apr 28, 2022 at 07:26:41AM -0400, Kevin A. McGrail wrote: We discussed this a year or two ago. The data on there is not sensitive and is cryptographically verified by spamassassin

Re: HTTPS for mirrors

2022-04-28 Thread Henrik K
On Thu, Apr 28, 2022 at 07:41:56AM -0400, Kevin A. McGrail wrote: > By default, the data is cryptographically verified. An admin has to > specifically turn off that feature. > > There's little benefits of using HTTPS in this specific setting and it's > just an extra requirement on our volunteer

Re: HTTPS for mirrors

2022-04-28 Thread Kevin A. McGrail
By default, the data is cryptographically verified. An admin has to specifically turn off that feature. There's little benefits of using HTTPS in this specific setting and it's just an extra requirement on our volunteer mirrors. It will add time, CPU load, and even a small amount of bandwidth

Re: HTTPS for mirrors

2022-04-28 Thread Henrik K
On Thu, Apr 28, 2022 at 07:26:41AM -0400, Kevin A. McGrail wrote: > We discussed this a year or two ago. The data on there is not sensitive and > is cryptographically verified by spamassassin before being used. Can you > name a single reason the data needs to be encrypted in transit? KAM It's

Re: HTTPS for mirrors

2022-04-28 Thread Kevin A. McGrail
:40:58PM +0200, Fossies Administrator wrote: > > On Wed, 27 Apr 2022, Henrik K wrote: > > > > > > > > There's really no reason these days for not using https. > > > > > > Only three mirrors work with it right now: > > > > > > sa-u

Re: HTTPS for mirrors

2022-04-28 Thread Henrik K
On Thu, Apr 28, 2022 at 12:40:58PM +0200, Fossies Administrator wrote: > On Wed, 27 Apr 2022, Henrik K wrote: > > > > > There's really no reason these days for not using https. > > > > Only three mirrors work with it right now: > > > > sa-updat

Re: HTTPS for mirrors

2022-04-28 Thread Fossies Administrator
On Wed, 27 Apr 2022, Henrik K wrote: There's really no reason these days for not using https. Only three mirrors work with it right now: sa-update.razx.cloud sa-update.pccc.com sa-update.mailfud.org Could maybe others prepare for it? sa-update seems to happily use https:// mirrors starting

HTTPS for mirrors

2022-04-27 Thread Henrik K
There's really no reason these days for not using https. Only three mirrors work with it right now: sa-update.razx.cloud sa-update.pccc.com sa-update.mailfud.org Could maybe others prepare for it? sa-update seems to happily use https:// mirrors starting from 3.4.0, so there shouldn't be any