Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-14 Thread Edd Barrett
On Mon, Mar 13, 2017 at 08:45:11AM +, Stuart Henderson wrote: > On 2017/03/12 17:57, Edd Barrett wrote: > > On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: > > > +# Elinks does not check SSL certificates properly! > > > +# Disable SSL support to protect our users. > > > +CONFIGURE_

Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-13 Thread Stuart Henderson
On 2017/03/12 17:57, Edd Barrett wrote: > On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: > > +# Elinks does not check SSL certificates properly! > > +# Disable SSL support to protect our users. > > +CONFIGURE_ARGS += --without-gnutls \ > > + --without-openssl > > A

Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-12 Thread Jeremie Courreges-Anglas
Edd Barrett writes: > On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: >> +# Elinks does not check SSL certificates properly! >> +# Disable SSL support to protect our users. >> +CONFIGURE_ARGS += --without-gnutls \ >> +--without-openssl > > Any comments on this?

Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-12 Thread Edd Barrett
On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: > +# Elinks does not check SSL certificates properly! > +# Disable SSL support to protect our users. > +CONFIGURE_ARGS +=--without-gnutls \ > + --without-openssl Any comments on this? Kill SSL support or kill elin

Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-10 Thread Edd Barrett
On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: > Index: Makefile > === > RCS file: /home/edd/cvsync/ports/www/elinks/Makefile,v > retrieving revision 1.37 > diff -u -p -r1.37 Makefile > --- Makefile 30 Jan 2017 10:06:55

Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-10 Thread Edd Barrett
Hi, The following email appeared in my inbox from the elinks-dev list (I can't link you to it because it seems all the elinks archives have either disappeared or are out of date). I've verified that elinks is not checking the validity of certificates by hitting https://www.pcwebshop.co.uk/ in bot