tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Cert validation in pkg_add



>  We have had one positive comment.  One person told me they would test
>  and comment, but haven't yet.  Another person in private mail was
>  vaguely positive but unconvinced about the rush.
> 
>  I'm still uncomfortable about the lack of other people really reading
>  and consdering impacts, given that this arose in month 3.

Let me come out strongly in favor then.

I think pkg_add should absolutely check certificates for PKG_PATHs with SSL and I think Taylor’s approach here is totally reasonable.

— 
Benny


Home | Main Index | Thread Index | Old Index