/srv/irclogs.ubuntu.com/2014/02/11/#ubuntu-installer.txt

* cjwatson writes a longish mail about thoughts for possible approaches to the debootstrappish part of bug 1135163, and then realises that he's argued himself round to the point where only a single option is plausible16:04
ubot2`Launchpad bug 1135163 in choose-mirror (Ubuntu) "d-i can't install against an https mirror" [High,In progress] https://launchpad.net/bugs/113516316:04
infinitycjwatson: Are you going to make --no-check-gpg imply --no-check-ssl, or add the latter as an explicit debootstrap option or some such?17:47
infinitycjwatson: (And then pass down a cmdline/preseed to trigger same, for people who don't care about baking certs into an installer or driver disk)17:48
cjwatsoninfinity: I already made debian-installer/allow_unauthenticated imply wget --no-check-certificate, indeed17:49
cjwatsonAt least for early stages; I still need to arrange to pass that to debootstrap, but it's easy enough17:49
infinitycjwatson: Sure, I meant for debootstrap.17:49
cjwatsondebootstrap has a --no-check-certificate option, so it's just a matter of having base-installer pass it.  Next on my list17:50
infinitycjwatson: I wonder if debootrap might want a --no-check-ssl, and then a --no-check-sigs that implies -ssl/-gpg for people who want to skip all checking at once.17:50
infinityOh, wait, it does?17:50
infinityOh, so it does.17:50
infinityI've never noticed that before.17:50
infinityCause I never thought it did SSL. :P17:51
infinityNeeeevermind, then.17:51
cjwatsonLooks like it was added in 201017:51
infinityExplains it.  I don't seem to notice new software features added after about 2002, unless they smack me in the face.17:52
cjwatsonIt may be worth having a separate preseedable question for disabling SSL checks, but I think I'll wait until somebody complains17:53
infinityMy bet is that's what the big G would prefer.17:54
infinityDriver disks or custom installers are both harder than a preseed when you're installing on a network that you trust.17:54
cjwatsonHm, you may be right.  If so I should probably do that now rather than later17:54
cjwatsonThe SSL check is weaker than GPG for most purposes17:55
infinityRight, AFAIR, their reason for wanting SSL wasn't anonymisation or security, but purely that they prefer not to run any HTTP services at all.17:55
infinitySo, having one unique snowflake HTTP Ubuntu mirror irks them.17:55
infinityBut I doubt they care AT ALL if it provides any security on top of the GPG checks.17:56
cjwatsonI shouldn't have mailed debian-mirrors@ about adding Mirrors.masterlist metadata for this - now I'm embroiled in arguments with people missing the point18:00

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!