Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

time to drop http from metalinks by default? #311

Open
nirik opened this issue Apr 3, 2022 · 5 comments
Open

time to drop http from metalinks by default? #311

nirik opened this issue Apr 3, 2022 · 5 comments

Comments

@nirik
Copy link
Member

nirik commented Apr 3, 2022

Given letsencrypt, it should be pretty easy for mirrors to have https anymore, so perhaps we should just switch over to that fully now?

How many http only mirrors are there left?

@adrianreber
Copy link
Member

How many http only mirrors are there left?

Not sure. The SQL query to get this is too complicated for me 😉 . There are 1200 http:// URLs in the database and 500 https://, however.

From what I see with new mirrors, there are still many HTTP only mirrors and especially for private mirrors HTTPS might be unnecessary complicated

@nirik
Copy link
Member Author

nirik commented Apr 5, 2022

Ah yeah, I didn't think of private ones... indeed that could be more difficult. ;(

Perhaps it's worth then just a post to the mirror-admin list asking everyone to make sure they have https and drop http if they do?

Or we could just close this... whatever you prefer.

@nirik
Copy link
Member Author

nirik commented Apr 13, 2024

Perhaps it's worth revisiting this now?

We could exempt the private ones and just enforce no http on public ones?

@adrianreber
Copy link
Member

We could make this a Fedora decision by changing the repository file.

CentOS Stream for example disables rsync in the metalink results: https://gitlab.com/redhat/centos-stream/rpms/centos-release/-/blob/c9s/centos.repo?ref_type=heads#L3

Fedora could do the same by only requesting https. Fedora could appen protocol=https to all metalink lines. Or maybe try it with rawhide first.

@nirik
Copy link
Member Author

nirik commented Apr 15, 2024

True... I guess the biggest place it's noticable is the website download isos...

The website link could/should just default to https. Will see if thats feasable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants