[Asterisk-code-review] BuildSystem: Allow fetch of PJProject without trust anchors. (asterisk[master])

Corey Farrell asteriskteam at digium.com
Mon Feb 12 02:29:02 CST 2018


Corey Farrell has posted comments on this change. ( https://gerrit.asterisk.org/8181 )

Change subject: BuildSystem: Allow fetch of PJProject without trust anchors.
......................................................................


Patch Set 1: Code-Review-1

I'm not sure this is an Asterisk bug.  fetch is the last option chosen, only used if wget and curl are not installed.  The bug report says that installing 'wget' is a work-around.  wget is installed for all supported platforms by ./contrib/scripts/install_prereq.  So I think FreeBSD users should just use wget until FreeBSD fixes fetch.

I do like your idea of adding checksum verification for all downloads but I think this should be in addition to HTTPS, not instead of.  Multiple layers of security is always best.


-- 
To view, visit https://gerrit.asterisk.org/8181
To unsubscribe, visit https://gerrit.asterisk.org/settings

Gerrit-Project: asterisk
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I573308fa11a69d28480b669971b5bfe66476fa60
Gerrit-Change-Number: 8181
Gerrit-PatchSet: 1
Gerrit-Owner: Alexander Traud <pabstraud at compuserve.com>
Gerrit-Reviewer: Alexander Traud <pabstraud at compuserve.com>
Gerrit-Reviewer: Corey Farrell <git at cfware.com>
Gerrit-Reviewer: Jenkins2
Gerrit-Comment-Date: Mon, 12 Feb 2018 08:29:02 +0000
Gerrit-HasComments: No
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.digium.com/pipermail/asterisk-code-review/attachments/20180212/9ab262dd/attachment.html>


More information about the asterisk-code-review mailing list