Re: git and https

2015-05-28 Thread Paul Wise
On Fri, May 29, 2015 at 7:40 AM, Russ Allbery wrote: > I'm fine with locking the doors. I'm not fine with paying protection > money to a Mafia goon who claims they'll lock your windows, and sort of > sometimes does. It's the extortion component that pisses me off about > HTTPS. LetsEncrypt will

Re: Bug#786902: O: ifupdown -- high level tools to configure network interfaces

2015-05-28 Thread roopa
On 5/28/15, 10:05 PM, Paul Wise wrote: On Thu, 2015-05-28 at 21:59 -0700, roopa wrote: We plan to post it for inclusion as an alternative to ifupdown (using the debian alternatives infrastructure), hoping to make it easier for people who may be interested in trying it out. Please see this page

Bug#787146: ITP: Gambatte - Game Boy and Game Boy Color emulator

2015-05-28 Thread Sergio benjamim Rocha filho
X-Debbugs-CC: debian-devel@lists.debian.org Package: wnpp Severity: wishlist * Package name : gambatte Version: 0.5.0 (r577) * URL : https://sourceforge.net/projects/gambatte/ https://github.com/sinamas/gambatte * License : GPL-2 Programming Lang: C++ Description: Game Boy and Game Boy Col

Re: Bug#786902: O: ifupdown -- high level tools to configure network interfaces

2015-05-28 Thread Paul Wise
On Thu, 2015-05-28 at 21:59 -0700, roopa wrote: > We plan to post it for inclusion as an alternative to ifupdown (using > the debian alternatives infrastructure), hoping to make it easier > for people who may be interested in trying it out. Please see this page for how to get ifupdown2 into Debi

Re: Bug#786902: O: ifupdown -- high level tools to configure network interfaces

2015-05-28 Thread roopa
On 5/27/15, 8:18 PM, Paul Wise wrote: On Thu, May 28, 2015 at 1:41 AM, Christoph Anton Mitterer wrote: Haven't tried systemd-networkd yet, but at least NM fails in even very simple cases (like resolving is broken, when I disconnect the wire and go back to wifi, etc. pp.) ... plus the whole desi

Bug#787143: ITP: ruby-minitest-excludes -- Ruby library that provides MiniTest extensions and unit tests helpers

2015-05-28 Thread Miguel Landaeta
Package: wnpp Severity: wishlist Owner: Miguel Landaeta * Package name: ruby-minitest-excludes Version : 2.0.0 Upstream Author : Ryan Davis * URL : https://github.com/seattlerb/minitest-excludes * License : MIT Programming Lang: Ruby Description : Ruby

Re: git and https

2015-05-28 Thread Russ Allbery
Clint Byrum writes: > Excerpts from Russ Allbery's message of 2015-05-27 22:23:02 -0700: >> If you aren't doing certificate pinning, I don't think you can really say >> this with a straight face. > The word is "avoids", it is not "eliminates". What ever happened to > defense in depth? There's no

Re: git and https

2015-05-28 Thread Clint Byrum
Excerpts from Russ Allbery's message of 2015-05-27 22:23:02 -0700: > Josh Triplett writes: > > > https:// avoids MITM; > > If you aren't doing certificate pinning, I don't think you can really say > this with a straight face. > The word is "avoids", it is not "eliminates". What ever happened t

Stepping back from the Debian XML/SGML team, effectively orphaning all my packages (docbook*, xml-core, xmlto, etc. pp)

2015-05-28 Thread Daniel Leidert
x-post Hi everybody, I was part of the Debian XML/SGML team [1] for quite some time and it was fun maintaining the whole DocBook toolchain. Unfortunately I'm not using it anymore and thus have lost interest in these packages. Now after Jessie has been released, I'm finally stepping back as mainta

Re: git and https

2015-05-28 Thread Tollef Fog Heen
]] Russ Allbery > Also, for people coming from Debian hosts talking to the Debian > infrastructure, at least in theory we *could* do certificate pinning, > which transforms HTTPS into a worthwhile security protocol. It's not > exactly trivial to work out the UI and integration problems, and it >

Bug#787114: ITP: pytest-httpbin -- Test an HTTP library against a local copy of httpbin.org

2015-05-28 Thread Vincent Bernat
Package: wnpp Severity: wishlist Owner: Vincent Bernat -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 * Package name: pytest-httpbin Version : 0.0.6 Upstream Author : Kevin McCarthy * URL : https://github.com/kevin1024/pytest-httpbin * License : Expat Progr

Bug#787113: ITP: httpbin -- HTTP Request and Response Service

2015-05-28 Thread Vincent Bernat
Package: wnpp Severity: wishlist Owner: Vincent Bernat -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 * Package name: httpbin Version : 0.2.1 Upstream Author : Runscope Community * URL : https://github.com/Runscope/httpbin * License : ISC Programming Lang:

Bug#787108: ITP: python-cmislib -- CMIS client library for Python

2015-05-28 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: python-cmislib Version : 0.5.1 Upstream Author : Apache Chemistry Project * URL : https://chemistry.apache.org/python/cmislib.html * License

Bug#787107: ITP: purl -- URL interrogation and manipulation

2015-05-28 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: purl Version : 1.0.3 Upstream Author : David Winterbottom * URL : https://pypi.python.org/pypi/purl * License : Expat Programming Lang

Re: git and https

2015-05-28 Thread Jeremy Stanley
On 2015-05-28 09:33:35 +0200 (+0200), Roland Mas wrote: > I understand that behemoths such as Iceweasel may take some time > to move, but maybe Git could be made to use the TLSA records in > DNSSEC? Postfix does make use of them, and SSH uses their SSHFP > cousins, so it's not completely an abstrac

Re: git and https

2015-05-28 Thread Russ Allbery
Roland Mas writes: > I understand that behemoths such as Iceweasel may take some time to > move, but maybe Git could be made to use the TLSA records in DNSSEC? > Postfix does make use of them, and SSH uses their SSHFP cousins, so it's > not completely an abstract idea. > Roland, > who spent so

Bug#787097: ITP: r-cran-futile.logger -- logging utility for GNU R

2015-05-28 Thread Andreas Tille
Package: wnpp Severity: wishlist Owner: Andreas Tille * Package name: r-cran-futile.logger Version : 1.4.1 Upstream Author : Brian Lee Yung Rowe * URL : http://cran.r-project.org/web/packages/futile.logger/ * License : LGPL Programming Lang: R Description

Re: Using build profiles in stretch?

2015-05-28 Thread Johannes Schauer
Hi, Quoting Helmut Grohne (2015-05-28 12:55:03) > On Thu, May 28, 2015 at 08:43:12AM +0200, Lucas Nussbaum wrote: > > This worked fine when I tested it locally because I use sbuild, but now > > that it is uploaded, I realize that: - pbuilder doesn't support it (which > > breaks the package on repr

Re: Bug#786902: O: ifupdown -- high level tools to configure network interfaces

2015-05-28 Thread Christoph Anton Mitterer
On Thu, 2015-05-28 at 11:18 +0800, Paul Wise wrote: > > Haven't tried systemd-networkd yet, but at least NM fails in even very > > simple cases (like resolving is broken, when I disconnect the wire and > > go back to wifi, etc. pp.) ... plus the whole design, that it tries to > > be the canonical

Re: Using build profiles in stretch?

2015-05-28 Thread Antonio Terceiro
On Thu, May 28, 2015 at 08:43:12AM +0200, Lucas Nussbaum wrote: > It seems the early support in dpkg confused me into thinking that it was fully > supported in stretch. > > So, the question is: should we wait until stretch is released to use build > profiles, to give time to all infrastructure too

Re: Using build profiles in stretch?

2015-05-28 Thread Helmut Grohne
On Thu, May 28, 2015 at 08:43:12AM +0200, Lucas Nussbaum wrote: > To fix #632776 (ruby-shoulda-context,gem2deb: Circular build-dependency), That's great. Please keep that. > This worked fine when I tested it locally because I use sbuild, but now that > it > is uploaded, I realize that: > - pbu

Bug#787080: ITP: libreoffice-online -- LibreOffice on-line

2015-05-28 Thread Rene Engelhard
Package: wnpp Severity: wishlist Owner: Rene Engelhard Filing this ITP because I am sure people will ask about this when it becomes official. It already appeared in a PM: http://blog.documentfoundation.org/2015/03/25/libreoffice-to-become-the-cornerstone-of-the-worlds-first-universal-productivity

Re: git and https

2015-05-28 Thread Wouter Verhelst
On Thu, May 28, 2015 at 10:30:58AM +0200, Tollef Fog Heen wrote: > ]] Wouter Verhelst > > > - Most importantly, you need to configure your webserver and SSL library > > so it disables outdated protocol versions, enables newer secure > > protocol versions (doing so in a way that older propriet

ITP: eso-pipelines -- ESO VLT Instrument pipeline collection (was: ITP: astromatic -- Astronomical pipeline software collection)

2015-05-28 Thread Ole Streicher
Control: retitle -1 "ITP: eso-pipelines -- ESO VLT Instrument pipeline collection" Oops, forgot to change the title... -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: https://lists.debian.o

Re: git and https

2015-05-28 Thread Tollef Fog Heen
]] Wouter Verhelst > - Most importantly, you need to configure your webserver and SSL library > so it disables outdated protocol versions, enables newer secure > protocol versions (doing so in a way that older proprietary clients > who don't speak those newer versions yet and make up the ma

Bug#787058: ITP: astromatic -- Astronomical pipeline software collection

2015-05-28 Thread Ole Streicher
Package: wnpp Severity: wishlist Owner: Ole Streicher X-Debbugs-Cc: debian-devel@lists.debian.org,debian-as...@lists.debian.org * Package name : eso-pipelines * URL : http://www.eso.org/sci/software/pipelines/ * License : public-domain Description : ESO VLT In

Re: git and https

2015-05-28 Thread Roland Mas
Russ Allbery, 2015-05-27 22:23:02 -0700 : > Josh Triplett writes: > >> https:// avoids MITM; > > If you aren't doing certificate pinning, I don't think you can really say > this with a straight face. > > It makes MITM moderately harder, at the cost of giving money to a bunch of > exploitative clo

Re: git and https

2015-05-28 Thread Wouter Verhelst
On Wed, May 27, 2015 at 12:20:03PM +0100, Rebecca N. Palmer wrote: > >Why? Which attack do you envision[...]that would > >be thwarted by https but not by signed commits? > I don't; I see https as easier and hence more likely to actually get used in > practice. Well, on that we disagree then, I sup

Bug#787054: ITP: python-django-hijack -- Allows superusers to login as and work on behalf of other users

2015-05-28 Thread Senthil Kumaran S
Package: wnpp Severity: wishlist Owner: Senthil Kumaran S * Package name: python-django-hijack Version : 1.0.7 Upstream Author : Philippe O. Wagner Yannik Ammann * URL : https://github.com/arteria/django-hijack * License : MIT Programmin