Re: [arch-general] secure package signing related websites

2012-03-05 Thread Florian Pritz
On 05.03.2012 10:04, Christian Hesse wrote: > Leonid Isaev on Sun, 4 Mar 2012 10:32:45 -0600: >> On Sun, 4 Mar 2012 14:56:43 +0100 >> Christian Hesse wrote: >> > Ionut Biru on Sun, 04 Mar 2012 12:57:53 +0200: >> > > On 03/04/2012 12:22 PM, Christian Hesse wrote: >> > > > I think it makes sense t

Re: [arch-general] secure package signing related websites

2012-03-05 Thread Christian Hesse
Leonid Isaev on Sun, 4 Mar 2012 10:32:45 -0600: > On Sun, 4 Mar 2012 14:56:43 +0100 > Christian Hesse wrote: > > > Ionut Biru on Sun, 04 Mar 2012 12:57:53 +0200: > > > On 03/04/2012 12:22 PM, Christian Hesse wrote: > > > > I think it makes sense to not allow pages related to package signing > >

Re: [arch-general] secure package signing related websites

2012-03-04 Thread Leonid Isaev
On Sun, 4 Mar 2012 14:56:43 +0100 Christian Hesse wrote: > Ionut Biru on Sun, 04 Mar 2012 12:57:53 +0200: > > On 03/04/2012 12:22 PM, Christian Hesse wrote: > > > I think it makes sense to not allow pages related to package signing > > > being delivered via http. Instead automatically redirect t

Re: [arch-general] secure package signing related websites

2012-03-04 Thread Christian Hesse
Ionut Biru on Sun, 04 Mar 2012 12:57:53 +0200: > On 03/04/2012 12:22 PM, Christian Hesse wrote: > > I think it makes sense to not allow pages related to package signing being > > delivered via http. Instead automatically redirect to https to avoid man > > in the middle attacks. First site that com

Re: [arch-general] secure package signing related websites

2012-03-04 Thread Ionut Biru
On 03/04/2012 12:22 PM, Christian Hesse wrote: > Hello everybody, > > (As I am not allowed to post to arch-dev-public resending it here.) > > ok, not really related to the keyring package, but it came to my mind when > installing it and while signing the key: > > I think it makes sense to not al

[arch-general] secure package signing related websites (was: Re: Keyring package for real)

2012-03-04 Thread Christian Hesse
Hello everybody, (As I am not allowed to post to arch-dev-public resending it here.) ok, not really related to the keyring package, but it came to my mind when installing it and while signing the key: I think it makes sense to not allow pages related to package signing being delivered via http.