Summary0000443: Download site not available through HTTPS
DescriptionBoth the Bareos main website ( ) and the bug tracker ( ) are available through HTTPS. Strangely enough, the domain which serves all the software packages and cryptographic OpenPGP keys for code signature verification ( ) is NOT available through HTTPS.

An attacker could therefore easily send your customers different OpenPGP keys and/or manipulated software packages which could very well result in a complete compromise in that customer's IT infrastructure. After all, we are talking about an enterprise backup system that usually has full access to filesystems on machines it is deployed on.
Steps To Reproduce1. Visit
2. A TLS warning appears complaining about the fact that the used X.509 certificate is only valid for the domain and not
Additional InformationSeriously, please fix this. Here are some possible solutions:

1. Install an additional certificate X.509 certificate for
2. Install a wildcard X.509 certificate which is valid for all the above-mentioned domains.
3. Serve your software packages and cryptographic OpenPGP keys through
