[Python-apps-team] Bug#861152: Bug#861725: unblock: nagstamon/2.0.1-4

Paul Wise pabs at debian.org
Wed May 3 10:49:55 UTC 2017


On Wed, 2017-05-03 at 12:24 +0200, Moritz Schlarb wrote:

> - This has been the behavior of the Nagstamon package since forever
> (which is not a valid argumentation point - I know, but it's still a fact)

There are two serious bugs here:

1) that certificates are not verified at least using CAs and or TOFU

2) that this fact was deliberately hidden from users

> What do you think?

I think we should enable the warnings in all suites.

Once verification is available, backport the patch to all suites.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: This is a digitally signed message part
URL: <http://lists.alioth.debian.org/pipermail/python-apps-team/attachments/20170503/2bd68fa9/attachment.sig>


More information about the Python-apps-team mailing list