View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0000159 | apt-panopticon | Bug | public | 2020-03-10 00:17 | 2020-03-10 00:34 |
Reporter | onefang | Assigned To | onefang | ||
Priority | high | Severity | major | Reproducibility | always |
Status | assigned | Resolution | open | ||
Product Version | 0.1 | ||||
Summary | 0000159: HTTPS -> HTTP redirects of /DEBIAN-SECURITY/ are actually valid. | ||||
Description | But I currently mark them as WARNING. There might be other similar things. | ||||
Tags | No tags attached. | ||||
Also I should rethink this a bit. Normally a redirection that changes the scheme would be legal, that's why people redirect to HTTPS in the first place. HTTP -> HTTPS on DNS-RR and for people with no apt-transport-https is ERROR. HTTPS -> HTTP for things where no HTTPS is allowed per Debian / Devuan policy is good, like DNS-RR. I'll have to read up on Debian mirror policy. |
|