Anonymous Login
2018-12-16 10:17 UTC

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0001724OpenClonkWebsite - Automated Buildspublic2017-08-20 11:40
Reportersphalerite 
Assigned To 
PrioritynormalSeverityminorReproducibilityalways
StatusacknowledgedResolutionopen 
Product Version 
Target Version9.0Fixed in Version 
Summary0001724: No secure download options
DescriptionNeither HTTPS downloads nor tarball signatures are available for download. This means that downloads can be MITMed to introduce malware and we have no way of verifying that the download has not been tampered with.
TagsNo tags attached.
Attached Files

-Relationships
+Relationships

-Notes

~0005073

Isilkor (developer)

Reminder sent to: Clonk-Karl, Newton

CC'ing ck and Newton on this because the bare engine binaries themselves are available via HTTPS, just the snapshots aren't.

~0005075

Newton (administrator)

Yes, our webhoster does not offer HTTPS (for a reasonable price). This won't change in the medium term.

The only option if we wanted HTTPS for the downloads would be to move the download archive and snapshots to Isilkor's server. I do not oppose this but of course this means to again rewrite all the release and snapshot build scripts.
If any of you two want to do this, you can notify CK or me so that we change the links on the website.

If not, this bug will be closed.

~0005076

sphalerite (reporter)

I'd be all for signed tarballs as well, it makes redistribution easier, doesn't require HTTPS support from anyone, and doesn't rely on the PKI.

~0005125

sphalerite (reporter)

Any chance of this happening?

~0005128

Isilkor (developer)

I'm all for moving the snapshots to autobuild.openclonk.org, which is already available via TLS only.
+Notes

-Issue History
Date Modified Username Field Change
2016-04-24 13:31 sphalerite New Issue
2016-04-24 13:31 sphalerite Status new => assigned
2016-04-24 13:31 sphalerite Assigned To => Isilkor
2016-04-24 13:34 Isilkor Note Added: 0005073
2016-04-24 13:34 Isilkor Assigned To Isilkor =>
2016-04-24 13:34 Isilkor Status assigned => acknowledged
2016-04-24 13:42 Newton Note Added: 0005075
2016-04-24 13:44 sphalerite Note Added: 0005076
2016-06-10 17:23 sphalerite Note Added: 0005125
2016-06-15 10:34 Isilkor Note Added: 0005128
2017-08-05 13:58 Maikel Target Version => 8.0
2017-08-20 11:40 Zapper Target Version 8.0 => 9.0
+Issue History