From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 108733 invoked by alias); 12 Mar 2019 14:58:49 -0000 Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner@cygwin.com Mail-Followup-To: cygwin@cygwin.com Received: (qmail 108724 invoked by uid 89); 12 Mar 2019 14:58:49 -0000 Authentication-Results: sourceware.org; auth=none X-Spam-SWARE-Status: No, score=-1.5 required=5.0 tests=AWL,BAYES_00,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE,SPF_PASS autolearn=ham version=3.3.1 spammy=burden, HX-Languages-Length:730, person X-HELO: mail-vs1-f49.google.com Received: from mail-vs1-f49.google.com (HELO mail-vs1-f49.google.com) (209.85.217.49) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Tue, 12 Mar 2019 14:58:48 +0000 Received: by mail-vs1-f49.google.com with SMTP id b17so1735934vsr.13 for ; Tue, 12 Mar 2019 07:58:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=p2Lh6LgwhqNZPpZXWLdQsTSXtsyG8bWcMpDSuDDcxe0=; b=h7k3HW/fQv76u71uzgO1RgVgc6zE6Q9rSBt/X9/aPWhH50t7cRUhw8wgVEpvaRVpfg kfUxK7uGfv34S5JrfSsQB8ILFuMyUhlJEFND7ReQ0F/rCNuvBQw3ukfYFMF0Nzt/C62L ybcdqyhyHJHBRV2orNX1IwjJopI8hwL493evcQDvzbFQFlwmqnvE4v/WrzytEfNPi3La E+0T66CGBWHCN/qkIRrJUHIS6BDSSt8/a/ULoz28QDHiE2yx+/znQ92e6MXEKb3ACnt7 nTBgXO3CwSjph4kyYn+mdwIk7GkXyE9ew17cDYXCRaMKSggispUaMkeW69ZG8CdaeRYJ fv1A== MIME-Version: 1.0 References: <1a840c2e-55ac-0ab4-66c4-a1f6a2c4f81a@Shaw.ca> <41f12842-ea43-ff63-a660-26ee3b497c63@SystematicSw.ab.ca> <1b570593-0ec7-0890-26ef-7e7468534f47@SystematicSw.ab.ca> In-Reply-To: From: Archie Cobbs Date: Tue, 12 Mar 2019 14:58:00 -0000 Message-ID: Subject: Re: SSL not required for setup.exe download To: Brian.Inglis@systematicsw.ab.ca, cygwin@cygwin.com Content-Type: text/plain; charset="UTF-8" X-IsSubscribed: yes X-SW-Source: 2019-03/txt/msg00291.txt.bz2 On Tue, Mar 12, 2019 at 9:32 AM Brian Inglis wrote: > > OTOH, if you download the file over HTTPS.. then your client supports > > SSL. Which is exactly what I'm saying should be mandatory. > > Forcing TLS means blocking anyone who for any reason can not use TLS: this is a > performance and support burden compared to allowing both HTTP:80 and HTTPS:443. OK. Personally I have trouble believing any such person exists. That is, a person who has access to an HTTP client, but not an HTTPS client, for the one-time operation of downloading setup.exe. What are they using, a TRS-80? Anyway no worries, I'm giving up on this issue. Too much inertia around here. -AC -- Archie L. Cobbs -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple