It’s fixed now.

Before it worked.

  • olympicyes@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    5 days ago

    If you go to the mirrors page you’ll see cdimage.debian.org under Sweden and it’s an http link. My guess is that the link is just misconfigured on the home page. It’s helpful to avoid https for things like this because it allows you to download updates on machines with outdated security software, eg TLS 1.0/1.1.

  • Cousin Mose@lemmy.hogru.ch
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    5 days ago

    I see this too and it’s caused by the actual server not having a certificate belonging to the domain. It’s likely a configuration problem (and okay) but I don’t like to take chances.

    If they offer a torrent, perhaps it’s better to use that for now.

  • SteveTech@programming.dev
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 days ago

    It seems like it’s fixed now, but if possible use one of the mirrors, so everyone’s not hitting that one server all that hard, it’s usually faster too.

    Or even better, use the torrent.

  • Red@reddthat.com
    link
    fedilink
    English
    arrow-up
    7
    ·
    5 days ago

    You can download it over http and check the SHA256SUMS.

    Or better yet torrent it and check the same sha256

    I can’t remember if it was always like that or not, but all the apt repos are the same. No SSL and verification via signing.

    • lengau@midwest.social
      link
      fedilink
      arrow-up
      5
      ·
      5 days ago

      Apt repos are like that for several reasons, one of which is that it allows DNS based mirroring without having to share a certificate. Another is that back when apt started out, HTTPS was pretty rare.

    • dunes@feddit.orgOP
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      edit-2
      5 days ago

      It seems like an odd choice if it’s not a mistake to put it on the first page and it’s not just a HTTP warning it’s an SSL warning that appears quite scary on Chromium browsers.

      But cool to know that apt repos don’t use SSL i knew they verified via signature but fought they had both.

    • EddyBot@discuss.tchncs.de
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      5 days ago

      Torrent programs already do checking hash checksums to determine if you got it 100%

      thats also the only reason to check your download with a provided hash checksum from a website… to check the intigrity of the download and not for safety reasons

      • Red@reddthat.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        Torrents verify that the data they downloaded is correct.
        That doesn’t mean the data that was used to create the torrent was correct. In this case I suggested downloading via torrent (because of http) and then checking the sha from the website to verify everything matches. If it does they you’ve got a good iso!