public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Yuri Vasilevski <yuri@ciencias.unam.mx>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] heads up: adding ca-certificates as a PDEPEND to openssl
Date: Fri, 30 Dec 2005 20:59:40 -0600	[thread overview]
Message-ID: <20051230205940.4903e1b7@edune.lan> (raw)
In-Reply-To: <200512301734.59151.vapier@gentoo.org>

Hi,

On Fri, 30 Dec 2005 17:34:59 -0500
Mike Frysinger <vapier@gentoo.org> wrote:

> just a heads up ... i'm going to be adding the ca-certificates package as a 
> PDEPEND to the openssl package so most everyone in Gentoo will end up with it 
> on their system
> 
> for those wondering what this is:
> http://packages.debian.org/unstable/misc/ca-certificates
> basically it's additional certificates that arent part of the default openssl 
> distribution

I'm not so sure that this is a good idea, as adding CA root
certificates is a way to make (good) money for some free projects and
unfortunately for some non free ones too. I'm not sure if openssl
charges certificate inclusion, but if it does this will interfere with
the founding policies (and then development) of openssl.

Now, being a little bit less ideological, I think it is perfectly ok to
add certificates from some organizations like CACert.org that try to
make security free for all Internet users as well as open source
projects' certificates (like debian ones). But it should be up to
businesses to buy they're way into openssl by the means of this
"sponsoring".

So my suggestions is to add root certificates only for non for profit
organizations. (For intermediate certificates that already have root
certificate bundled with openssl it ok in all cases). Or at last don't
make it a RDEPEND but an einfo "you may want to intall X for Y reason".


> this will inadvertently fix this fun bug:
> http://bugs.gentoo.org/101457
> and probably more in the future

In this king of cases it is probably better to ask upstream to bug
they're CA to "sponsor" openssl or use some free CA.

Yuri.
-- 
gentoo-dev@gentoo.org mailing list



  reply	other threads:[~2005-12-31  3:02 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-12-30 22:34 [gentoo-dev] heads up: adding ca-certificates as a PDEPEND to openssl Mike Frysinger
2005-12-31  2:59 ` Yuri Vasilevski [this message]
2005-12-31  4:17   ` Curtis Napier
2005-12-31  4:38     ` Mike Frysinger
2005-12-31  4:47     ` Doug Goldstein

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20051230205940.4903e1b7@edune.lan \
    --to=yuri@ciencias.unam.mx \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox