Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Download the nginx secure key to verify the package

>

>cd /tmp/

>wget http://nginx.org/keys/nginx_signing.key

Verify a package with a key you got over http? Am I the only one who noticed this?



A bit silly yes, but nginx.org doesn't support https, which is slightly more silly and rules out most other options.


What's the right way to do this?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: