Kev Needham wrote:
The state of the art in prophecy, indeed.

The foreseeable future means just that. We don't plan on removing the
preference to disable signing enforcement for ESR builds based off of
45, and at this point in time I don't see anything currently that would
make me think that would change for future releases. I would be lying to
you, however, if I said there is no chance that wouldn't change.

Thanks for the info - that's the clearest statement I've seen about add-on signing and ESR so far :-)

The page at https://wiki.mozilla.org/Addons/Extension_Signing is rather vague on the subject - it states:

"The first ESR version to support signing will be Firefox ESR 45. The current plan is to have ESR work like 40-42, with a preference that can turn off enforcement, but that may change in the future."

It would be good to get that reworded to state that the preference _will_ be in ESR 45

Also, later it states in the FAQ section:

"What about private add-ons used in enterprise environments?

We haven't announced our plan for this case yet. Stay tuned. In the interim, ESR will not support signing at least until version 45, which won't come out until 2016."

I guess that should be updated as it is now 2016 - and ESR 45 is only a few weeks away ... so I think it's about time the plans are announced :-)

I understand that some orgs are required by policy to maintain unsigned
add-ons/keep code in-house, and there are no better alternatives that I
could consider at this point. I'll also invite anyone who does this to
send me feedback directly on what the concerns are for signing them
using the API are - I can guess (wrt policy, infosec, etc.), but direct
feedback always helps.

I would say your guesses are correct ...

IMHO keeping the preference in all future ESR (major) versions would be the acceptable plan for enterprise environments

Thanks

James Pearson
_______________________________________________
Enterprise mailing list
[email protected]
https://mail.mozilla.org/listinfo/enterprise

To unsubscribe from this list, please visit https://mail.mozilla.org/listinfo/enterprise 
or send an email to [email protected] with a subject of 
"unsubscribe"

Reply via email to