Bug 96827 - website www.spice-space.org: downloads are not secured at all
Summary: website www.spice-space.org: downloads are not secured at all
Status: RESOLVED FIXED
Alias: None
Product: Spice
Classification: Unclassified
Component: RFE (general) (show other bugs)
Version: unspecified
Hardware: Other All
: medium critical
Assignee: Spice Bug List
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-05 22:04 UTC by Christian Stadelmann
Modified: 2016-09-06 12:34 UTC (History)
1 user (show)

See Also:
i915 platform:
i915 features:


Attachments

Description Christian Stadelmann 2016-07-05 22:04:38 UTC
Currently, the website http://www.spice-space.org/ is not encrypted nor does it provide any signatures for downloads. This is an easy target for man-in-the-middle-attacks.

Please
1. make this site available through HTTPS (and only HTTPS)
2. provide gpg signatures for downloads
Comment 1 Christophe Fergeau 2016-07-06 09:44:04 UTC
(In reply to Christian Stadelmann from comment #0)
> Currently, the website http://www.spice-space.org/ is not encrypted nor does
> it provide any signatures for downloads. This is an easy target for
> man-in-the-middle-attacks.
> 
> Please
> 1. make this site available through HTTPS (and only HTTPS)

Yes, having https access has been on the TODO for a while

> 2. provide gpg signatures for downloads

Some downloads do have GPG signatures, see the .sig/.sign files on http://www.spice-space.org/download/releases/ , I agree this should be done for all new releases, which is far from being the case currently
Comment 2 Frediano Ziglio 2016-08-01 16:50:15 UTC
I don't know if it can help. Somebody suggested this service to me https://letsencrypt.org/about/. But probably we can get a certificate from RedHat.
Comment 3 Christophe Fergeau 2016-09-06 12:34:04 UTC
https://www.spice-space.org/download/ can now be accessed through https.
There is one remaining issue with https://spice-space.org/download/ which uses an invalid certificate. We are trying to fix that.


Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.