Package: mirrors
Severity: normal

Dear Maintainer,

* What led up to the situation?

I tried to access

https://ftp.pl.debian.org/debian

in firefox, which gave

'Warning: Potential Security Risk Ahead'

* What exactly did you do (or not do) that was effective (or
ineffective)?

I selected 'advanced', 'accept the risk and continue', and continued through
to 'View Certificate'.

* What was the outcome of this action?

I found the entries:

Common Name  ftp.task.gda.pl

Subject Alt Names

DNS Name   debian.task.gda.pl
DNS Name   ftp.task.gda.pl
DNS Name   pl.archive.ubuntu.com
DNS Name   pl.releases.ubuntu.com
DNS Name   releases.ubuntu.task.gda.pl
DNS Name   ubuntu.task.gda.pl


* What outcome did you expect instead?

I expected that an ssl certificate for ftp.pl.debian.org would have been
considered to be secure. The bug is presumably because the certificate
only includes the six domain names listed above, and not ftp.pl.debian.org
itself.


* Suggested solution: update DNS records.

Cheers
Boud

Reply via email to