Chris Marusich <cmmarus...@gmail.com> writes:

> Radoslav Petrov <m...@edno.moe> writes:
>
>> About a proper fix: IMO iced3 JDK Guix definition needs to process
>> "java.security" file for the SunPKCS11 provider to override the
>> JAVA_HOME definition with the file in the current version/dir/instance
>> of the Guix package (I'm not sure for the correct term). But this have
>> to be done on each update/upgrade of NSS package. So I'm not so sure
>> about the proper way to fix this packaging problem.
>
> This sounds right to me.  If I'm hearing you correctly, there is a
> configuration file in the output of the icedtea package which needs to
> be updated whenever the nss package is updated.  I believe the correct
> way to accomplish that is to use "static composition" or "late static
> composition" [1].  I'm sure a convenient mechanism for this exists in
> Guix, but since I haven't done it myself, I'm not sure of the details.
>
> [1] See section 7.1.1 in Eelco Dolstra's thesis:
> http://nixos.org/%7Eeelco/pubs/phd-thesis.pdf

We are already genarting the keystore for IcedTea.  It just fails for
IcedTea 3, which is why it’s disabled there.  IcedTea 2 should work just
fine.

-- 
Ricardo

GPG: BCA6 89B6 3655 3801 C3C6  2150 197A 5888 235F ACAC
http://elephly.net


Reply via email to