LibreOffice.org and application use http-protocol

Hello,

I noticed that libreoffice.org does not default to an https-connection, but that the SSL certificate is installed. Is it possible to force SSL connections?

Also, I noticed that the application connects to update.libreoffice.org using port 80. This could potentially allow man-in-the-middle-attacks, and install altered software when updating. Is it possible to update only over https? (and for all other connections attempted by libreoffice)

Thanks!!

If you are using Firefox browser you can try out HTTPS Everywhere. It can be installed from here: HTTPS Everywhere Firefox Addon

I use it all the time and libreoffice.org always connects via HTTPS (as do many other sites). Note that you can add ‘exceptions’ to any sites that you don’t want to connect to via HTTPS, but you really only need to do that very occasionally. In several years of use I’ve only had to do that once. To all intents and purposes it works for me without my intervention.

Thanks for your reply. I indeed use HTTPS Everywhere, but still the LibreOffice program connects via HTTP instead of HTTPS when updating software.

Okay. I just stumbled across this which seems to imply that you might be able to do what you want: SSL Enforcer. I have no experience using that but if it does what it says it looks promising.

It could be the case that not being able to connect via HTTPS while doing software updating is a limitation at the server end - updating via HTTPS may not be enabled at all at the server. I suppose the only way around to remain secure in that scenario is using a VPN.