1 |
On Tue, Feb 5, 2013 at 7:06 PM, Rich Freeman <rich0@g.o> wrote: |
2 |
> My knee-jerk reaction is that your browser has a bug. It thinks that |
3 |
> it is appropriate to sound alarms for unauthenticated SSL connections |
4 |
> but not for unauthenticated non-SSL connections. A workaround is to |
5 |
> emerge ca-certificates. |
6 |
> |
7 |
> That said, I do understand your concerns (my pet peeves with the CA |
8 |
> infrastructure and modern browsers notwithstanding). |
9 |
|
10 |
I understand your concerns as well, but I think practicality should |
11 |
win over purity here. |
12 |
|
13 |
> I'm sure the trustees would be interested as long as this was aligned |
14 |
> with infra. I'd reach out to them first and work out a plan - paying |
15 |
> for it is likely to not be a big issue (and we've had offers of |
16 |
> donated certificates as well). |
17 |
|
18 |
I'm sure some infra people read this list, but I'll CC them here just |
19 |
to be sure. |
20 |
|
21 |
Cheers, |
22 |
|
23 |
Dirkjan |