Joe Rosato via plug on 20 Sep 2019 08:34:50 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] The lock down?! Uhh.. why?


If you work with either RHEL or OracleLinux - has anyone noticed the recent push for https for repos?

For example, OracleLinux:
https://oracle-base.com/articles/linux/download-the-latest-oracle-linux-repo-file
note: the pre 2019 (http) and post 2019 (https)

As for RHEL there has been the push for RHSM away from RHN. Take a look at the repo files -  https, not http.

What is the thinking here? Can't tell if I'm just old school or if this is.. well.. bad. The gpgcheck for signatures covers fears of bogus repos. Why add https?

Joe



___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug