Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDownload of signature is not secure via sf.net #907
Comments
marmarek
added
bug
C: other
P: major
labels
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
marmarek
Mar 8, 2015
Member
Comment by Nukama on 18 Oct 2014 10:28 UTC
Thoroughly study [[VerifyingSignatures]] and understand the issues with chains of trust. See discussion in #203.
|
Comment by Nukama on 18 Oct 2014 10:28 UTC |
marmarek
added
the
notanissue
label
Mar 8, 2015
marmarek
closed this
Mar 8, 2015
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
marmarek commentedMar 8, 2015
Reported by anonymous on 18 Oct 2014 08:16 UTC
Hi,
since you distribute the iso signatures via sourceforge, they're not fetched using https.
So while the cubes website is in nice and shiny https-green, it's not possible to see if i fetched a valid iso.
Are you doing regular checks on the checksum files?
And even then. Please publish them on the site and via https.
Migrated-From: https://wiki.qubes-os.org/ticket/907