Gentoo Archives: gentoo-dev

From: Yuri Vasilevski <yuri@×××××××××××××.mx>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] heads up: adding ca-certificates as a PDEPEND to openssl
Date: Sat, 31 Dec 2005 03:02:10
Message-Id: 20051230205940.4903e1b7@edune.lan
In Reply to: [gentoo-dev] heads up: adding ca-certificates as a PDEPEND to openssl by Mike Frysinger
1 Hi,
2
3 On Fri, 30 Dec 2005 17:34:59 -0500
4 Mike Frysinger <vapier@g.o> wrote:
5
6 > just a heads up ... i'm going to be adding the ca-certificates package as a
7 > PDEPEND to the openssl package so most everyone in Gentoo will end up with it
8 > on their system
9 >
10 > for those wondering what this is:
11 > http://packages.debian.org/unstable/misc/ca-certificates
12 > basically it's additional certificates that arent part of the default openssl
13 > distribution
14
15 I'm not so sure that this is a good idea, as adding CA root
16 certificates is a way to make (good) money for some free projects and
17 unfortunately for some non free ones too. I'm not sure if openssl
18 charges certificate inclusion, but if it does this will interfere with
19 the founding policies (and then development) of openssl.
20
21 Now, being a little bit less ideological, I think it is perfectly ok to
22 add certificates from some organizations like CACert.org that try to
23 make security free for all Internet users as well as open source
24 projects' certificates (like debian ones). But it should be up to
25 businesses to buy they're way into openssl by the means of this
26 "sponsoring".
27
28 So my suggestions is to add root certificates only for non for profit
29 organizations. (For intermediate certificates that already have root
30 certificate bundled with openssl it ok in all cases). Or at last don't
31 make it a RDEPEND but an einfo "you may want to intall X for Y reason".
32
33
34 > this will inadvertently fix this fun bug:
35 > http://bugs.gentoo.org/101457
36 > and probably more in the future
37
38 In this king of cases it is probably better to ask upstream to bug
39 they're CA to "sponsor" openssl or use some free CA.
40
41 Yuri.
42 --
43 gentoo-dev@g.o mailing list

Replies