[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Q: Use https for {deb,security}.debian.org by default



Hi,

On 8/19/21 3:38 PM, Hideki Yamane wrote:

  Now deb.debian.org and security.debian.org provide https access
  but created sources.list file use http for those. Is there any
  reason to use http instead of https for them? (traffic, policy,
  etc...) If not, how about to change it?

There is little benefit to do so, it just increases processing overhead and breaks caching proxies, most importantly transparent proxies in large hosting companies and large container deployments.

For the most part, users would configure https if they are behind a corporate firewall that disallows http, or modifies data in-flight so signature verification fails, everyone else is better off using plain http.

   Simon

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


Reply to: