Hosting distfiles on HTTPS w/Let's Encrypt - how?

Marcin Cieslak saper at saper.info
Thu Jun 1 23:06:15 UTC 2017


On Thu, 1 Jun 2017, Jov wrote:

> can you dowload the file distfiles/INIT.2014-12-24.tgz
> <https://distfile.net/local-ports-distfiles/INIT.2014-12-24.tgz> using
> browser such as chrome?

Yes, Firefox, IE11, no certificate warnings.

> be sure to use full chain cert file,I rember I had similar problem and use
> full chain cert fixed.

(Without the root CA):


Certificate chain                                                
 0 s:/CN=marcincieslak.com                                       
   i:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3         
 1 s:/C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3         
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3 

How should fetch know that "=Digital Signature Trust Co./CN=DST Root CA X3" is
a valid CA if none have been installed?

Marcin Cieślak
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3663 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20170601/28e4e7fa/attachment.bin>


More information about the freebsd-ports mailing list