rdo-infra / rdo-release

RDO release repository
12 stars 16 forks source link

Use https in repo files by default #1

Closed cgwalters closed 9 years ago

cgwalters commented 9 years ago

While for the release repository we do have RPM GPG checking enabled, there are various attacks one can mount if one controls unsigned repodata; http://theupdateframework.com/ talks about that.

Fedora does set up a redirect, but this ensures we use it from the start for stronger security.