Re: [coreboot] force https on review.coreboot.org

2015-04-16 Thread Timothy Pearson
On 04/16/2015 08:57 AM, Alexander Couzens wrote: Hi, review isn't forcing https. Can we please do this? Otherwise stealing cookies is posibble. Review supports https. There is atm an CACert based certificate and CaCert isn't included in the default root keychain. Thus a normal user will shown

Re: [coreboot] force https on review.coreboot.org

2015-04-16 Thread Patrick Georgi via coreboot
2015-04-16 15:57 GMT+02:00 Alexander Couzens lyn...@fe80.eu: than let us change to StartSSL or someother SSL authority. I'll ask CNNIC. I heard they have good offers. PPS. Please write a +1 if you're supporting this opinion. Please don't. Patrick -- Google Germany GmbH, ABC-Str. 19, 20354

[coreboot] force https on review.coreboot.org

2015-04-16 Thread Alexander Couzens
Hi, review isn't forcing https. Can we please do this? Otherwise stealing cookies is posibble. Review supports https. There is atm an CACert based certificate and CaCert isn't included in the default root keychain. Thus a normal user will shown a big fat warning, not to connect to

Re: [coreboot] force https on review.coreboot.org

2015-04-16 Thread The Gluglug
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Alexander, On 16/04/15 14:57, Alexander Couzens wrote: Hi, review isn't forcing https. Can we please do this? Otherwise stealing cookies is posibble. Review supports https. There is atm an CACert based certificate and CaCert isn't included

Re: [coreboot] force https on review.coreboot.org

2015-04-16 Thread thomasg
On Fri, Apr 17, 2015 at 2:01 AM, The Gluglug i...@gluglug.org.uk wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Alexander, On 16/04/15 14:57, Alexander Couzens wrote: Hi, review isn't forcing https. Can we please do this? Otherwise stealing cookies is posibble. Review supports