Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
-
None
Description
The download pages should really use https for KEYS, sigs and hashes
Also there is no description of how to verify releases.
Could link to:
https://www.apache.org/dyn/closer.cgi#verify