setup SSL

self-signed is perfect, just post the hashes here and optionally GPG sign it

Or you could buy a 5$ SSL cert on namecheap with bitcoins

Or are you referring to a downloadable version?
i trust a self-signed more than a bought one, as self-signed only someone that hacks him can make fake certs, if you buy it, tonfs of organizations + ppls can create fake certs...