Gentoo Archives: gentoo-dev

From: solar <solar@g.o>
To: Andrea Barisani <lcars@g.o>
Cc: security@g.o, gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: ca-certificates PDEPEND
Date: Mon, 09 Jan 2006 16:11:41
Message-Id: 1136822918.11648.58.camel@onyx
In Reply to: [gentoo-dev] ca-certificates PDEPEND by Andrea Barisani
1 On Mon, 2006-01-09 at 16:55 +0100, Andrea Barisani wrote:
2 > Regarding the inclusion of ca-certificates as a PDEPEND (yeah a brief
3 > exchange of emails already happened on -dev but since it's not so easy to
4 > track it I'm lagging behind on this) I would like to express that I really
5 > don't like the fact that we are "trusting" cacert.org certs (among others)
6 > without providing it as a choice.
7 >
8 > Despite all the political views that we can throw in favour of a "cacert.org
9 > are trying to make the SSL certs world less evil" argument this is some major
10 > policy that we are supporting and it shouldn't be taken that lightly (I don't
11 > remember such a major confrontation about this) and I really don't think this
12 > should be a default policy but rather user's choice. Technically cacert.org
13 > is not a recognized CA in the "proper" way (and don't point that a proper CA
14 > is a lame concept and a snake oil thing..this is not the point).
15
16 > [CCing security@g.o because this concerns the team as well imho.]
17 >
18 > Just my 2 eurocent.
19 >
20 > P.S.
21 > I know that firefox doesn't trust /etc/ssl/certs by default, dunno about
22 > konqueror. The point is still relevant though.
23
24
25 Do you think the PDEPEND of the ca-certs should be tied to a USE= flag?
26 If so should it be a 'no*certs' flag or a USE=cacerts ?
27 --
28 solar <solar@g.o>
29 Gentoo Linux
30
31 --
32 gentoo-dev@g.o mailing list

Replies

Subject Author
[gentoo-dev] Re: ca-certificates PDEPEND Andrea Barisani <lcars@g.o>