Bug#954044: libcpan-perl-releases-perl: Please verify server identity via SSL

gregor herrmann gregoa at debian.org
Wed Apr 29 22:29:35 BST 2020


On Wed, 29 Apr 2020 08:46:44 +0200, Salvatore Bonaccorso wrote:

> > Will you please turn on the verify_SSL attribute in HTTP::Tiny?
> 
> Unless mistaken, HTTP::Tiny is only used in tools/ which are installed
> as examples on how one can potentially use CPAN::Perl::Releases. 
> 
> Still, this should be adressed, but we won't diverge here from
> upstream, so this should be reported upstream/forwarded and then once
> fixed upstream close the bug.

Also, as discussed in #954089, this should probably be changed in
(the two instances of) HTTP::Tiny and not in each and every single
consumer.


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   NP: David Bowie: Golden Years
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: Digital Signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20200429/2ee1d7ee/attachment.sig>


More information about the pkg-perl-maintainers mailing list