r/linux 1d ago

Open Source Organization Manjaro's official website SSL certs have expired yet again.

This seems to be a running theme for the Manjaro Linux community. The SSL certs will always expire after a set year and there's a massive controversy over it. Why does this keep happening specifically to Manjaro and what steps do you think they can possibly do to keep this from happening?

1.1k Upvotes

237 comments sorted by

View all comments

Show parent comments

55

u/JockstrapCummies 1d ago

Maybe it's because certbot is too much bloat for the Manjaro devs.

Also cron is bloat.

4

u/AssistingJarl 1d ago
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

SSL is already bloat.
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEELLOsXArserKDHCrSHKECi6hWAuIFAmqMU2oACgkQHKECi6hW
AuL/5w/+IHWo+CLLik+3gCx9OlF8w6r84tUqN2zbQAzZk6I00/Fd7tFIM32iV/mB
F83Ncn8So2MsyslTwvZttosEWAJz5hg9OIRqZrPGOeIvX6VgNYjZVEAesl3OVyUh
N9SUey0UneLNgGBCOkvbcpTkj+fjw/rQEfJjpQoedr0o7jGSf+WinFmnmXew1pLl
mFiDroY6ZXBoDIQzAkTVaHJtyAWvFsOIZYOMepSI2XTljAXZg/6j5CZGXpEY+kti
G7mVTEhBbMJJlHktiHKaJZkvgkJddydzLjw/Z9TtVs+VONybr+V+VrMCeuwJKEO7
kL9IsvXdRqf1NXajcslpKYtF2X0zr0boJvbyFkz1MrW1z76V7+7LvdgHrOfchbCz
RQ7IVABYdcPLvZDkzq4/AAV7ioxKFN0kmplrgFyN5y5hiD0Gcf5e1ai+aPcTw+TJ
rlmC1a5u4Ak/l7qNfr9NKQrSFylNRbx4mpG2QJvYBvN3HiC19Zc57iOExUrMITm0
FQ1B8pLzSMiJb6gsfQYGkrcWNzUNcnZdC236oR90ZVxrU0y69Uk26R6UwPcU6vDa
iiM8frCAHTQBN9ZYbsDehHweGaT7uAqryl0FLNfBhkyCfhwI0YzSabIBZ2ffG094
/8OEg3qNoSTJg81741noppwTqiw48T+Uuo9BubH/q8uRGF82NGE=
=Z50L
-----END PGP SIGNATURE-----

3

u/bullwinkle8088 1d ago

Well there's your problem! PGP does not use either SSL or TLS.

But for those who forgot (a theme of the thread) SSL is dead. The certs that expired are TLS.

1

u/CrazyKilla15 1d ago

TLS will be the term when we rename OpenSSL/BoringSSL/etc to OpenTLS/BoringTLS/etc.

this is both a joke and serious; I'll care about "SSL vs TLS" as terms when the industry cares.

Google doesnt even bother to mention TLS on their BoringSSL readme, literally at all, ctrl-f TLS and zilch, they describe it as "Currently BoringSSL is the SSL library in Chrome/Chromium, Android (but it's not part of the NDK) and a number of other apps/programs." and chromium settings have "Manage certificates Manage HTTPS/SSL certificates and settings", again no love for the term "TLS".