Re: packages, libfetch, and SSL



On Mon, Oct 22, 2007 at 10:07:33AM +0800, Adrian Chadd wrote:
You can't (easily) cache data over SSL. Well, you can't use a HTTP
proxy that doesn't break the SSL conversation and cache the updates.

As someone who occasionally makes sure that distribution updates
through a Squid proxy actually caches said updates, I'd really prefer
you didn't stick package contents behind SSL.

Fair enough.

Now, we could take another approach of PGP-signing packages instead, but
all the efforts I've seen to integrate PGP with the package management
system in the past haven't gone anywhere. The changes above seem to be
a bit more trivial than inventing a package-signing infrastructure and
putting gpg or a BSD-licensed clone into base. Perhaps using SSL to sign
packages and having a baked-in key would work as well.

Considering its a solved problem (mostly!) in other distributions, and
their updates are very cachable, why not do this?

Sounds fine to me - I'll take a closer look at this. I'd still like
to see the root CA certs merged into base so libfetch can be fixed.
Does anyone object to just using the ones currently provided by the
ca_root_nss port?

_______________________________________________
freebsd-hackers@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: packages, libfetch, and SSL
    ... proxy that doesn't break the SSL conversation and cache the updates. ... As someone who occasionally makes sure that distribution updates ... you didn't stick package contents behind SSL. ...
    (freebsd-hackers)
  • Re: packages, libfetch, and SSL
    ... The lowest-impact way to fix this, I think, is to use SSL for pkg_adds. ... You can't cache data over SSL. ... proxy that doesn't break the SSL conversation and cache the updates. ... you didn't stick package contents behind SSL. ...
    (freebsd-hackers)
  • Re: Feature Proposal: Rolling Updates (was Re: WHY I WANT TO STOP USING FEDORA!!!)
    ... kinks are worked out, the new package requires libfoo.9, then libfoo.9 ... everything that required libfoo.7 also has to be moved into updates. ... When you update Fedora ... I am well aware of libraries. ...
    (Fedora)
  • Re: Binary RHEL Updates available free !
    ... > logo/trademark on a GPL package deny redistibution of that package because ... And note these are only the updates to keep a system ... Open Source is what it's all about. ...
    (linux.redhat)
  • Re: Easy way to update Fedora
    ... >>What is the easiest way to update Fedora. ... >>about yum but it has never worked for me, ... > packages or type a package name ... > UPDATES TO SYSTEM AND PROGRAMS: ...
    (Fedora)