Gentoo Archives: gentoo-dev

From: Andrea Barisani <lcars@g.o>
To: solar <solar@g.o>
Cc: security@g.o, gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: ca-certificates PDEPEND
Date: Mon, 09 Jan 2006 16:15:24
Message-Id: 20060109161231.GP6055@sole.infis.univ.trieste.it
In Reply to: [gentoo-dev] Re: ca-certificates PDEPEND by solar
1 On Mon, Jan 09, 2006 at 11:08:38AM -0500, solar wrote:
2 > On Mon, 2006-01-09 at 16:55 +0100, Andrea Barisani wrote:
3 > > Regarding the inclusion of ca-certificates as a PDEPEND (yeah a brief
4 > > exchange of emails already happened on -dev but since it's not so easy to
5 > > track it I'm lagging behind on this) I would like to express that I really
6 > > don't like the fact that we are "trusting" cacert.org certs (among others)
7 > > without providing it as a choice.
8 > >
9 > > Despite all the political views that we can throw in favour of a "cacert.org
10 > > are trying to make the SSL certs world less evil" argument this is some major
11 > > policy that we are supporting and it shouldn't be taken that lightly (I don't
12 > > remember such a major confrontation about this) and I really don't think this
13 > > should be a default policy but rather user's choice. Technically cacert.org
14 > > is not a recognized CA in the "proper" way (and don't point that a proper CA
15 > > is a lame concept and a snake oil thing..this is not the point).
16 >
17 > > [CCing security@g.o because this concerns the team as well imho.]
18 > >
19 > > Just my 2 eurocent.
20 > >
21 > > P.S.
22 > > I know that firefox doesn't trust /etc/ssl/certs by default, dunno about
23 > > konqueror. The point is still relevant though.
24 >
25 >
26 > Do you think the PDEPEND of the ca-certs should be tied to a USE= flag?
27 > If so should it be a 'no*certs' flag or a USE=cacerts ?
28
29 USE=cacerts sounds the proper course of action to me.
30
31 --
32 Andrea Barisani <lcars@g.o> .*.
33 Gentoo Linux Infrastructure Developer V
34 ( )
35 PGP-Key 0x864C9B9E http://dev.gentoo.org/~lcars/pubkey.asc ( )
36 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E ^^_^^
37 "Pluralitas non est ponenda sine necessitate"
38 --
39 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] Re: ca-certificates PDEPEND Henrik Brix Andersen <brix@g.o>
Re: [gentoo-dev] Re: ca-certificates PDEPEND Jakub Moc <jakub@g.o>
Re: [gentoo-dev] Re: ca-certificates PDEPEND Kalin KOZHUHAROV <kalin@××××××××.net>