Re: https everywhere.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Fri, May 15, 2015 at 03:44:39PM -0400, James B. Byrne wrote:
> What are the plans for the CentOS repos with respect to authentication
> and https everywhere?  At the moment it is a trivial exercise to
> perform a MTM attack during a yum update over http.

Since the packages themselves are signed, what risk are you concerned
about?

-- 
Matthew Miller
<mattdm@xxxxxxxxxxxxxxxxx>
Fedora Project Leader
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos




[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux