1 |
On Mon, 2006-01-09 at 16:55 +0100, Andrea Barisani wrote: |
2 |
> Regarding the inclusion of ca-certificates as a PDEPEND (yeah a brief |
3 |
> exchange of emails already happened on -dev but since it's not so easy to |
4 |
> track it I'm lagging behind on this) I would like to express that I really |
5 |
> don't like the fact that we are "trusting" cacert.org certs (among others) |
6 |
> without providing it as a choice. |
7 |
> |
8 |
> Despite all the political views that we can throw in favour of a "cacert.org |
9 |
> are trying to make the SSL certs world less evil" argument this is some major |
10 |
> policy that we are supporting and it shouldn't be taken that lightly (I don't |
11 |
> remember such a major confrontation about this) and I really don't think this |
12 |
> should be a default policy but rather user's choice. Technically cacert.org |
13 |
> is not a recognized CA in the "proper" way (and don't point that a proper CA |
14 |
> is a lame concept and a snake oil thing..this is not the point). |
15 |
|
16 |
> [CCing security@g.o because this concerns the team as well imho.] |
17 |
> |
18 |
> Just my 2 eurocent. |
19 |
> |
20 |
> P.S. |
21 |
> I know that firefox doesn't trust /etc/ssl/certs by default, dunno about |
22 |
> konqueror. The point is still relevant though. |
23 |
|
24 |
|
25 |
Do you think the PDEPEND of the ca-certs should be tied to a USE= flag? |
26 |
If so should it be a 'no*certs' flag or a USE=cacerts ? |
27 |
-- |
28 |
solar <solar@g.o> |
29 |
Gentoo Linux |
30 |
|
31 |
-- |
32 |
gentoo-dev@g.o mailing list |