4 ms·
Current software maintainer here. We have almost zero control over the webserver; it's run by a completely separate group of people. We can change some of the
by fifteen_letters 10y ago
Current software maintainer here.
We have almost zero control over the webserver; it's run by a completely separate group of people. We can change some of the content, but next to nothing of the server config itself.
(I realize that may sound strange to those of you who have never worked with any DoD organizations. Imagine going to one of the largest bureaucracies on the planet and saying, "We want you to change something.")
So yeah, none of us are happy about the current situation. Trying to distribute security-oriented software via a website with a SHA-1 cert signed by a root cert that has to be installed separately... the irony is nearly poetic.
Hoping to move to a completely different web host (still DoD, just different) before the end of the year. Most of us would be like, "we could do that in a day, plus DNS TTL expirations," but when they're not actually in combat, the DoD moves at... well, they move at the speed of government! :-)
- excalibur 10y agoLooks like they've since replaced it with a SHA256 cert. It was issued on the 22nd, so apparently they were already in the process of fixing it when this was posted to HN.