-
Bug
-
Resolution: Done
-
None
-
None
-
None
I noticed that on the new jboss.org site:
http://www.jboss.org/products/
People can now download our official product bits. The initial download URL, e.g.:
http://www.jboss.org/download-manager/file/jboss-eap-6.2.0.GA-installer.jar
Has a http URL. While you are eventually redirected to download the actual bits from access.cdn.redhat.com, it doesn't look good from a security perspective that the initial download link is not https. Could you please make all such download links use https?
There are also no checksums provided to verify the product bits. Please show checksums for all downloads, similar to CSP, e.g.:
- is blocked by
-
CGW-530 Add REST API that allows the download manager to be the source of truth for all downloads
- Done
-
CGW-692 Add REST API that exposes md5 and sha-256 file checksums, file size, file type, file name (human readable), any grouping needed and whether to display on www.jboss.org to the download Manager
- Done