Re: AOO Security Features without Mozilla

2013-10-23 Thread Herbert Duerr
Hi Pedro, Really nice to see nss being split soon. I hope we can use an external nss too as the one we include internally is somewhat outdated and potentially insecure. Absolutely. For the same reason the internal NSS should be updated. Would you be interested in doing it? You did a great

Re: AOO Security Features without Mozilla

2013-10-23 Thread Herbert Duerr
Hi Andrew, On 22.10.2013 20:00, Andrew Rist wrote: On 10/22/2013 7:15 AM, Herbert Dürr wrote: [...] With these new insights I suggest to remove both the enable-mozilla and its eventual replacement enable-mozab-module before losing much more time on that topic. The sooner the better. +1 This

Re: AOO Security Features without Mozilla

2013-10-23 Thread janI
On 23 October 2013 13:57, Herbert Duerr h...@apache.org wrote: Hi Pedro, Really nice to see nss being split soon. I hope we can use an external nss too as the one we include internally is somewhat outdated and potentially insecure. Absolutely. For the same reason the internal NSS should

Re: AOO Security Features without Mozilla

2013-10-23 Thread Herbert Duerr
On 23.10.2013 14:05, janI wrote: On 23 October 2013 13:57, Herbert Duerr h...@apache.org wrote: [..] Really nice to see nss being split soon. I hope we can use an external nss too as the one we include internally is somewhat outdated and potentially insecure. Absolutely. For the same

Re: AOO Security Features without Mozilla

2013-10-23 Thread Jürgen Schmidt
On 10/23/13 2:05 PM, janI wrote: On 23 October 2013 13:57, Herbert Duerr h...@apache.org wrote: Hi Pedro, Really nice to see nss being split soon. I hope we can use an external nss too as the one we include internally is somewhat outdated and potentially insecure. Absolutely. For the

Re: AOO Security Features without Mozilla

2013-10-23 Thread Herbert Duerr
On 22.10.2013 22:33, Andrea Pescetti wrote: Herbert Dürr wrote: [1] https://issues.apache.org/ooo/show_bug.cgi?id=85356 [2] https://issues.apache.org/ooo/show_bug.cgi?id=63270 [3] https://issues.apache.org/ooo/show_bug.cgi?id=91079 This is an interesting reality check and I'm afraid the project

Re: AOO Security Features without Mozilla

2013-10-23 Thread Kay Schenk
On Tue, Oct 22, 2013 at 4:30 AM, Herbert Dürr h...@apache.org wrote: About everyone who ever built OpenOffice in the last couple of years wondered why an almost complete (and obsolete/unmaintained/ancient) version of Mozilla Seamonkey was needed when building OpenOffice with its security

AOO Security Features without Mozilla

2013-10-22 Thread Herbert Dürr
About everyone who ever built OpenOffice in the last couple of years wondered why an almost complete (and obsolete/unmaintained/ancient) version of Mozilla Seamonkey was needed when building OpenOffice with its security features enabled such as support for password protected documents. The

Re: AOO Security Features without Mozilla

2013-10-22 Thread janI
On 22 October 2013 13:30, Herbert Dürr h...@apache.org wrote: About everyone who ever built OpenOffice in the last couple of years wondered why an almost complete (and obsolete/unmaintained/ancient) version of Mozilla Seamonkey was needed when building OpenOffice with its security features

Re: AOO Security Features without Mozilla

2013-10-22 Thread Herbert Dürr
On 22.10.2013 13:46, janI wrote: On 22 October 2013 13:30, Herbert Dürr h...@apache.org wrote: [...] Since issue 91209 the mozilla address books were disabled on Mac altogether anyway, so on Mac we could rid AOO of its heavy Seamonkey dependency really soon without removing any features by

Re: AOO Security Features without Mozilla

2013-10-22 Thread janI
On 22 October 2013 16:15, Herbert Dürr h...@apache.org wrote: On 22.10.2013 14:22, Herbert Dürr wrote: On 22.10.2013 13:46, janI wrote: On 22 October 2013 13:30, Herbert Dürr h...@apache.org wrote: [...] Since issue 91209 the mozilla address books were disabled on Mac altogether anyway,

Re: AOO Security Features without Mozilla

2013-10-22 Thread Pedro Giffuni
Hello; Really nice to see nss being split soon. I hope we can use an external nss too as the one we include internally is somewhat outdated and potentially insecure. While on the subject of replacing mozilla addressbook, just thought I'd remind about the analysis done by Andre while we were

Re: AOO Security Features without Mozilla

2013-10-22 Thread Andrea Pescetti
Herbert Dürr wrote: [1] https://issues.apache.org/ooo/show_bug.cgi?id=85356 [2] https://issues.apache.org/ooo/show_bug.cgi?id=63270 [3] https://issues.apache.org/ooo/show_bug.cgi?id=91079 This is an interesting reality check and I'm afraid the project lost users that depended on that