Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

use https for apt.syncthing.net as well #7

Open
anarcat opened this issue Mar 17, 2016 · 2 comments
Open

use https for apt.syncthing.net as well #7

anarcat opened this issue Mar 17, 2016 · 2 comments

Comments

@anarcat
Copy link

anarcat commented Mar 17, 2016

while the release key is hosted on https://syncthing.net/release-key.txt (which is behind HTTPS), it's probably a little ackward to have that key in a different location (i personnally was surprised at first).

so it would be useful to encrypt traffic to apt.syncthing.net. With let's encrypt now public, it's pretty easy and free to get certificates for any number of domains...

low priority, probably.

@calmh
Copy link
Member

calmh commented Mar 18, 2016

apt.syncthing.net is actually fully functional on HTTPS, the links just haven't been updated (and it provides no extra security for the actual APT repo as I understand it).

I don't personally see anything awkward with having our key on syncthing.net. Remember that this key signs the Github releases as well and predates the apt.syncthing.net setup by a long while.

@anarcat
Copy link
Author

anarcat commented Mar 18, 2016

On 2016-03-18 04:36:14, Jakob Borg wrote:

apt.syncthing.net is actually fully functional on HTTPS, the links just haven't been updated (and it provides no extra security for the actual APT repo as I understand it).

well, it provide a little more security: an eavesdropper will not know
what you download (although that's easy to guess because syncthing is
probably the only thing on this http server ;)

also, it is more consistent to host the APT key there, and that (apt key
authentication) is important extra security.

a.

From the age of uniformity, from the age of solitude, from the age of
Big Brother, from the age of doublethink - greetings!
- Winston Smith, 1984

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants