aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--ChangeLog.md5
-rw-r--r--SBO-Lib/lib/SBO/Lib/Download.pm2
2 files changed, 6 insertions, 1 deletions
diff --git a/ChangeLog.md b/ChangeLog.md
index 61481ba..fd5285b 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -9,6 +9,11 @@ All notable changes to this project will be documented in this file.
- Download's are retried from a third party on failure. Allow the user to
configure the third party source or disable this feature.
+### Security
+
+ - Check SSL certificates when downloading. Oddly, this was previously
+ disabled with '--no-check-certificate'.
+
## [2.8.0] - 2025-01-28
### Added
diff --git a/SBO-Lib/lib/SBO/Lib/Download.pm b/SBO-Lib/lib/SBO/Lib/Download.pm
index 331949b..fd337e2 100644
--- a/SBO-Lib/lib/SBO/Lib/Download.pm
+++ b/SBO-Lib/lib/SBO/Lib/Download.pm
@@ -172,7 +172,7 @@ sub get_distfile {
for my $link (@links) {
unlink $filename if -f $filename;
- if (system('wget', '--no-check-certificate', '--tries=5', $link) != 0) {
+ if (system('wget', '--tries=5', $link) != 0) {
if (not %$fail) {
# The failure from the first source is apparently what is important.
$fail = {msg => "Unable to wget $link.\n", err => _ERR_DOWNLOAD};