[Python-apps-team] Bug#861152: Bug#861725: unblock: nagstamon/2.0.1-4
Paul Wise
pabs at debian.org
Wed May 3 10:49:55 UTC 2017
On Wed, 2017-05-03 at 12:24 +0200, Moritz Schlarb wrote:
> - This has been the behavior of the Nagstamon package since forever
> (which is not a valid argumentation point - I know, but it's still a fact)
There are two serious bugs here:
1) that certificates are not verified at least using CAs and or TOFU
2) that this fact was deliberately hidden from users
> What do you think?
I think we should enable the warnings in all suites.
Once verification is available, backport the patch to all suites.
--
bye,
pabs
https://wiki.debian.org/PaulWise
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: This is a digitally signed message part
URL: <http://lists.alioth.debian.org/pipermail/python-apps-team/attachments/20170503/2bd68fa9/attachment.sig>
More information about the Python-apps-team
mailing list