On 14/07/2019 22.25, Christoph wrote:
The instructions on:
https://www.knot-resolver.cz/download/
read:
"
wget
https://secure.nic.cz/files/knot-resolver/knot-resolver-release.deb
dpkg -i knot-resolver-release.deb
apt update && apt install -y knot-resolver
"
these instructions result in an http://.. URL in:
/etc/apt/sources.list.d/knot-resolver-latest.list
I'd suggest to change it to https://..
Thanks for the feedback, we'll consider it. I'm a little hesitant, since
I recall there were some issues with OBS's https - maybe some of their
mirrors don't support it. In their "official" instructons [1], they use
http as well for the packages.
In any case, if you're worried about security, rather than
privacy/confidentiality, let me assure you that the packages are signed
by PGP. The signing key is part of the knot-resolver-release package,
which you downloaded securely over https.
[1] -
https://software.opensuse.org//download.html?project=home%3ACZ-NIC%3Aknot-r…
--
Tomas Krizek
PGP: 4A8B A48C 2AED 933B D495 C509 A1FB A5F7 EF8C 4869