From owner-freebsd-security@freebsd.org Wed Dec 6 01:07:58 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EC8FDE8A073 for ; Wed, 6 Dec 2017 01:07:58 +0000 (UTC) (envelope-from yonas@fizk.net) Received: from mail-it0-x229.google.com (mail-it0-x229.google.com [IPv6:2607:f8b0:4001:c0b::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id BB94C7C05A for ; Wed, 6 Dec 2017 01:07:58 +0000 (UTC) (envelope-from yonas@fizk.net) Received: by mail-it0-x229.google.com with SMTP id r6so5182087itr.3 for ; Tue, 05 Dec 2017 17:07:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fizk.net; s=google; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-transfer-encoding:content-language; bh=AADFD//m9KYcuefTkuBCg3iDpCBciS/93LLUXdFBGHw=; b=hgggrR549RXkJFREsBYhK3/vOOZTTe6uqkIN57MaE2oLOI6ewq+SSaQ0sERX7sqrPy U31Mcd9vv8oyfhlYAWLOzY6CunzzpaZd/PWX79Sn/F7n9z5aAZcEPRQCEBqTOWXwhpfV OqlicFTAWZ6UvHVEFkKBRbvJkFJ1UhM8J1Fe8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=AADFD//m9KYcuefTkuBCg3iDpCBciS/93LLUXdFBGHw=; b=ewoqXEXnQEHVwW/SjdoucMCCxC36ZKsIogHTAbIp6EjKKOr+BgmaQSReeHTbmY+wRR 6vTzrLuaMzKSIspHLyWLJSqiwXqGfJIfD0RgwFpMUCY9zbsTn9TfXevOikIqlvG8aaro Wqx7nS9dA4Sfm31bLKOpqE4bzQQcnIV70xo8OQlOjoXR3Yblc1mENDEsR12AR6DHLCoL bVulyIrIp2SJszpiqdRXzPt63jVSKEGjT3H3ljPchAuKgY6bR1Nt6qvFSAAxNZDgi8xz ttxZbcooT04FJU2kZvOfRyr4h6Bcqpwwr447yKViiGX5rLC/6FglANODHLyQxpd8VsDZ spQQ== X-Gm-Message-State: AKGB3mLiomGFAlSVklURGquLYttiqE4KjdB5AXr5DDYbuRDSWa1/iX/f W3wFZ/UarsSuma4rtMD8buBM5TC6gPc= X-Google-Smtp-Source: AGs4zMZqwJl9DjtrOUm19qBq7IK38wSWJCpTTagDMvSumDzHQaU/b3HXaHCRxZh/4bnv1AtqWBtnmQ== X-Received: by 10.36.123.134 with SMTP id q128mr21677921itc.80.1512522477807; Tue, 05 Dec 2017 17:07:57 -0800 (PST) Received: from [192.168.0.200] (CPEf0f2494a5cf3-CMf0f2494a5cf0.cpe.net.cable.rogers.com. [174.117.121.225]) by smtp.gmail.com with ESMTPSA id i63sm807360itb.35.2017.12.05.17.07.56 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 05 Dec 2017 17:07:56 -0800 (PST) Subject: Re: http subversion URLs should be discontinued in favor of https URLs To: freebsd-security@freebsd.org References: <97f76231-dace-10c4-cab2-08e5e0d792b5@rawbw.com> From: Yonas Yanfa Message-ID: <93c35d96-157a-c017-e646-0b32ec803abb@fizk.net> Date: Tue, 5 Dec 2017 20:01:41 -0500 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0 MIME-Version: 1.0 In-Reply-To: <97f76231-dace-10c4-cab2-08e5e0d792b5@rawbw.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Content-Language: en-US X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Dec 2017 01:07:59 -0000 On 12/05/2017 15:59, Yuri wrote: > I suggested this PR, but it got rejected: > https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=224097 > I would also prefer HTTPS over HTTP, but aren't signed commits what we're really looking for? Are individual commits in SVN digitally signed? Git has this ability, but it appears SVN does not. We have https://github.com/freebsd/freebsd but I don't see any signed commits. This might be a good reason to finally abandon SVN. Yonas