6 ms·
There's something I find really off-putting about a tool that's going to be managing private keys having dependencies that point to the master branch of various
by Freaky 10y ago
There's something I find really off-putting about a tool that's going to be managing private keys having dependencies that point to the master branch of various third party git repositories.
It also unconditionally tries to listen on ports 80, 402, 443, 552 and 4402 whenever it completes a challenge, even if you have absolutely no intention of using any of these verification methods, so there's a lot of moving parts most of which you don't want.
I made a FreeBSD port, but thought twice about submitting it: https://github.com/Freaky/ports/tree/master/security/acmetool https://github.com/Freaky/ports/tree/master/security/acmetoo...
- Sir_Cmpwn 10y agoWell, it's written in Go, so it's statically linked. Which helps with the whole master branch thing. It is weird that it attempts to listen on all of those ports, though.
- cyphar 10y agoIt being written in Go doesn't make "just pull the latest code from master from my dependencies at build time" a good thing. They should use vendoring and pin tagged releases.