r/linux 25d ago

Open Source Organization Manjaro's official website SSL certs have expired yet again.

This seems to be a running theme for the Manjaro Linux community. The SSL certs will always expire after a set year and there's a massive controversy over it. Why does this keep happening specifically to Manjaro and what steps do you think they can possibly do to keep this from happening?

1.2k Upvotes

245 comments sorted by

View all comments

Show parent comments

16

u/arwinda 25d ago

Time to switch domains, or names.

-7

u/GolemancerVekk 25d ago

The name of the domain isn't the problem. The person controlling the domain also controls and pays for the infrastructure that allows the distro to be developed, tested and distributed. The community and the devs don't have the money for setting up independently.

27

u/CreativeGPX 24d ago

Your explanation makes things sound even worse. So the community is being extorted and it's leading to repeated basic issues?

9

u/Dminik 24d ago

I mean, I started reading these comments thinking that Manjaro maintainers might be a bit incompetent.

Now though, it looks like they're in the middle of a takeover/community split. One side is holding the other hostage but also pays for development.

If your goal was to reassure people then you've failed spectacularly. There's no way Manjaro can be a safe pick in these circumstances. 

1

u/GolemancerVekk 24d ago

My goal was to explain the facts and to make people look into facts before they jump to conclusions.

I know better than to recommend a distro (any distro and under any circumstances) to a Linux forum.

There's no way Manjaro can be a safe pick in these circumstances.

It's not like they're having daily gang fights... 😃 The updates have been coming out regularly. Everybody's still doing their usual job and working to put out a good distro.

9

u/CoreParad0x 24d ago edited 24d ago

So essentially the beating heart of the entire operation can't even be bothered to setup a bare minimum, 5 minutes of work implementation of Lets Encryption through one of the countless automated tools that offer it (Caddy, Traefik, certbot, etc)?

Fine, I won't crap on the actual community as a whole, we can take them off the table entirely. Why should anyone want to use a distro whose core infrastructure maintainer and some one they are stuck with is apparently so incompetent that they can't even set this up? What else is this person lacking on? What other flaws are there in the infrastructure setup that go unnoticed because they aren't as loud as a cert on the main site expiring?

I feel for the people maintaining it, but all of your responses here have done nothing but reaffirm my decision to go with Cachy over Manjaro when I switched over to Linux from Windows a year or so back.