Re: Proposed F19 Feature: Shared System Certificates

2013-01-29 Thread Petr Pisar
On 2013-01-28, Florian Weimer wrote: > On 01/28/2013 03:45 PM, Petr Pisar wrote: >> On 2013-01-25, Florian Weimer wrote: >>> On 01/24/2013 12:30 PM, Stef Walter wrote: >>> So yes, as noted in the 'Detailed Description' of the feature, long term we hope to follow this up with further wor

Re: Proposed F19 Feature: Shared System Certificates

2013-01-28 Thread Florian Weimer
On 01/28/2013 03:45 PM, Petr Pisar wrote: On 2013-01-25, Florian Weimer wrote: On 01/24/2013 12:30 PM, Stef Walter wrote: So yes, as noted in the 'Detailed Description' of the feature, long term we hope to follow this up with further work to make all the crypto libraries be able to process th

Re: Proposed F19 Feature: Shared System Certificates

2013-01-28 Thread Petr Pisar
On 2013-01-25, Florian Weimer wrote: > On 01/24/2013 12:30 PM, Stef Walter wrote: > >> So yes, as noted in the 'Detailed Description' of the feature, long term >> we hope to follow this up with further work to make all the crypto >> libraries be able to process the information in its entirety. > >

Re: Proposed F19 Feature: Shared System Certificates

2013-01-25 Thread Stef Walter
On 01/25/2013 04:19 PM, Florian Weimer wrote: > On 01/24/2013 12:30 PM, Stef Walter wrote: > >> So yes, as noted in the 'Detailed Description' of the feature, long term >> we hope to follow this up with further work to make all the crypto >> libraries be able to process the information in its enti

Re: Proposed F19 Feature: Shared System Certificates

2013-01-25 Thread Florian Weimer
On 01/24/2013 12:30 PM, Stef Walter wrote: So yes, as noted in the 'Detailed Description' of the feature, long term we hope to follow this up with further work to make all the crypto libraries be able to process the information in its entirety. Okay. In the long term, it might make sense to o

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Kai Engert
On Thu, 2013-01-24 at 08:27 -0800, Samuel Sieb wrote: > On 01/23/2013 07:05 AM, Jaroslav Reznik wrote: > > = Features/SharedSystemCertificates = > > https://fedoraproject.org/wiki/Features/SharedSystemCertificates > > > > Feature owner(s): Kai Engert , Stef Walter > > > > > > Make NSS, GnuTLS, O

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Samuel Sieb
On 01/23/2013 07:05 AM, Jaroslav Reznik wrote: = Features/SharedSystemCertificates = https://fedoraproject.org/wiki/Features/SharedSystemCertificates Feature owner(s): Kai Engert , Stef Walter Make NSS, GnuTLS, OpenSSL and Java share a default source for retrieving system certificate anchors a

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Bill Nottingham
Kai Engert (k...@kuix.de) said: > On Wed, 2013-01-23 at 16:31 -0500, Bill Nottingham wrote: > > Essentially, how will we know whether apps work transparently with the > > library changes, and/or if there are apps that are hardcoding old > > locations/methods somewhere? > > we're not yet ready to

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Kai Engert
On Wed, 2013-01-23 at 16:31 -0500, Bill Nottingham wrote: > Essentially, how will we know whether apps work transparently with the > library changes, and/or if there are apps that are hardcoding old > locations/methods somewhere? Bill, we're not yet ready to shake hands, we're starting and giv

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Stef Walter
On 01/24/2013 09:12 AM, Florian Weimer wrote: > On 01/23/2013 04:05 PM, Jaroslav Reznik wrote: > >> OpenSSL: p11-kit tool will extract trusted certificate PEM blocks >> from the >> PKCS#11 trust module. >> These extracted certificates will be placed in a location so >> that

Re: Proposed F19 Feature: Shared System Certificates

2013-01-24 Thread Florian Weimer
On 01/23/2013 04:05 PM, Jaroslav Reznik wrote: OpenSSL: p11-kit tool will extract trusted certificate PEM blocks from the PKCS#11 trust module. These extracted certificates will be placed in a location so that they can be consumed by OpenSSL by default. T

Re: Proposed F19 Feature: Shared System Certificates

2013-01-23 Thread Bill Nottingham
Jaroslav Reznik (jrez...@redhat.com) said: > OpenSSL: p11-kit tool will extract trusted certificate PEM blocks from > the > PKCS#11 trust module. > These extracted certificates will be placed in a location so that > they > can be consumed by OpenSSL by default. >

Proposed F19 Feature: Shared System Certificates

2013-01-23 Thread Jaroslav Reznik
= Features/SharedSystemCertificates = https://fedoraproject.org/wiki/Features/SharedSystemCertificates Feature owner(s): Kai Engert , Stef Walter Make NSS, GnuTLS, OpenSSL and Java share a default source for retrieving system certificate anchors and black list information. This is an initial bu