-
Notifications
You must be signed in to change notification settings - Fork 21
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Server TLS configuration is broken and vulnerable #144
Comments
|
For the record, I also still see this problem here. I'm getting this when running emacs -q after adding adding the Marmalade repo (https://marmalade-repo.org/packages/): This is after running package-list-packages with the Marmalade repo configured, running under emacs -q. Hitting "always" in that dialog creates the following file in .emacs.d/network-security.data: There are two distinct problems here:
Problem 1 is this issue. The reason why it works in Firefox and Chromium is that they cache intermediate certificates like COMODO's. Problem 2 is a bug in Emacs, so not a concern here, but I figured I would share my workaround in case people want to verify the fingerprint. |
|
Problem still present on GNU Emacs 25.2.1, FreeBSD 11.1-RELEASE amd64. |
|
Is this thing on? |
|
@cabo Yeah but no-one is steering ;) |
|
I have posted a user workaround to https://emacs.stackexchange.com/a/35502/2701. The server should still be configured so this is unnecessary, though. |


See my other comment and the report from SSL Labs
@nicferrier seems to be missing in action, is there anybody with access to the server configuration?
The text was updated successfully, but these errors were encountered: