Control: forwarded -1 https://savannah.gnu.org/bugs/index.php?43501
On 2014-10-29 21:26:39 +0100, intrigeri wrote:
> Then, keeping #745836 as a wishlist bug to track the missing feature,
> and creating a clone about the more important (and more likely to be
> fixed here) documentation bug.
>
> Re
Control: found -1 1.16-1
Control: tag -1 + upstream
Control: clone -1 -2
Control: severity -1 wishlist
Control: retitle -2 wget manpage doesn't warn that certificate revocation lists
are not checked
Hi,
[hoping I got all the Control stanzas right..]
Vincent Lefevre wrote (28 Apr 2014 09:11:42 G
> This bug isn't on expired certificates, but on the revoked ones.
> The www.cloudflarechallenge.com test is now obsolete because the
> certificate has expired (wget 1.15 checks that, so no bugs here
> for expired certificates). Two tests with revoked certificates
> are still working:
>
> https:
This indeed looks like a bug in 1.15, because 1.13 and 1.14 recognize the
expired certificate:
$ wget www.cloudflarechallenge.com
--2014-08-19 13:41:45-- http://www.cloudflarechallenge.com/
Resolving www.cloudflarechallenge.com (www.cloudflarechallenge.com)...
107.170.194.215
Connecting to www.
On 2014-08-19 13:43:26 +0400, Vlad Orlov wrote:
> This indeed looks like a bug in 1.15, because 1.13 and 1.14
> recognize the expired certificate:
>
> $ wget www.cloudflarechallenge.com
> --2014-08-19 13:41:45-- http://www.cloudflarechallenge.com/
> Resolving www.cloudflarechallenge.com (www.clou
Control: severity -1 grave
On 2014-04-28 09:38:42 +0200, Raphael Geissert wrote:
> It is not a bug, it is a missing feature.
It's a bug because it doesn't behave as documented (contrary to curl,
where the way to check for certificate revocation is described in the
man page). Certificate checking
Control: severity -1 wishlist
Control: tags -1 security
On 25 April 2014 19:46, Vincent Lefevre wrote:
> Package: wget
> Version: 1.15-1
> Severity: grave
> Tags: security
> Justification: user security hole
>
> Certificate revocation is not checked: wget downloads
[...]
It is not a bug, it is a
Package: wget
Version: 1.15-1
Severity: grave
Tags: security
Justification: user security hole
Certificate revocation is not checked: wget downloads
https://www.cloudflarechallenge.com/
without any warning or error, contrary to Firefox (and to Chromium
when the CRLSet is up-to-date).
-- Syste
8 matches
Mail list logo