Ian Hinder just pointed out to me that our Einstein Toolkit thorn list as well as our beginners' tutorial use https for anonymous access to various svn repositories. This often leads to problems when certificates are either not installed correctly, or when the local svn installation cannot verify the certificates because the certificate is too new. We discussed this before, and decided that the best way to avoid this problem is to use plain http for anonymous checkout. Since all code is public this does not seem to be a security issue.
However, our thorn list still uses https in many cases. I have just updated our thorn list to use http instead of https for anonymous access, essentially adding an AUTH_URL for every URL, and modifying the URL to use http instead of https. Only SimFactory and LSUThorns cannot be accessed via plain http.
Should we make this modification before the release? I have tested the resulting thorn list, and find no problems with it; if anything, the checkout is now faster. This does not make any changes to the content of our software, but only changes the way in which the repositories are accessed. I would vote in favour, since (a) we decided to do this some time ago, and (b) testing this is easy.
I attach the new einsteintoolkit.th for your convenience.
-erik
I support this change. I just tested the new thornlist from New York and it worked fine here. It was also about 25% faster than the other ET_2010_11 thornlist.
Eric
On Mon, Nov 22, 2010 at 07:48:05PM -0500, Erik Schnetter wrote:
when the local svn installation cannot verify the certificates because the certificate is too new.
It is sad, but I have to agree that this seems to be more of an issue than I would like it to be, and we cannot do anything about it.
Should we make this modification before the release?
I support this even for the release. I tested the attached thornlist and it worked without problems.
Frank
On Mon, Nov 22, 2010 at 10:00 PM, Frank Loeffler knarf@cct.lsu.edu wrote:
On Mon, Nov 22, 2010 at 07:48:05PM -0500, Erik Schnetter wrote:
when the local svn installation cannot verify the certificates because the certificate is too new.
It is sad, but I have to agree that this seems to be more of an issue than I would like it to be, and we cannot do anything about it.
Should we make this modification before the release?
I support this even for the release. I tested the attached thornlist and it worked without problems.
I committed the new thorn list to the release branch.
-erik
users@lists.einsteintoolkit.org