GNU bug report logs - #21382
[PATCH] Use HTTPS for package repo URLs

Previous Next

Package: emacs;

Reported by: Francois Marier <francois <at> fmarier.org>

Date: Mon, 31 Aug 2015 00:22:01 UTC

Severity: wishlist

Done: Lars Ingebrigtsen <larsi <at> gnus.org>

Bug is archived. No further changes may be made.

Full log


Message #11 received at 21382 <at> debbugs.gnu.org (full text, mbox):

From: Ted Zlatanov <tzz <at> lifelogs.com>
To: Glenn Morris <rgm <at> gnu.org>
Cc: 21382 <at> debbugs.gnu.org, Francois Marier <francois <at> fmarier.org>
Subject: Re: bug#21382: [PATCH] Use HTTPS for package repo URLs
Date: Thu, 05 Nov 2015 14:36:42 -0500
On Mon, 31 Aug 2015 12:02:09 -0400 Glenn Morris <rgm <at> gnu.org> wrote: 

GM> Francois Marier wrote:

>> In order to avoid having users pull emacs packages over HTTP (where they can
>> be intercepted and modified by network attackers),
...
>> I have changed the default URLs for the package repositories to use HTTPS.

GM> Thanks for the patch, but more is needed than just unconditionally
GM> changing http to https. See discussion in

GM> http://lists.gnu.org/archive/html/emacs-devel/2015-05/msg00110.html

Francois, would you be interested in leading the work on those items?
I'll assist any way I can but I am unable to do it myself.

Ted




This bug report was last modified 5 years and 335 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.