Proposed F19 Feature: Shared System Certificates

Kai Engert kaie at kuix.de
Thu Jan 24 15:40:39 UTC 2013


On Wed, 2013-01-23 at 16:31 -0500, Bill Nottingham wrote: 
> Essentially, how will we know whether apps work transparently with the
> library changes, and/or if there are apps that are hardcoding old
> locations/methods somewhere?


Bill, 

we're not yet ready to shake hands, we're starting and giving you the
little finger.

Today we have a world that seems unorganized, where multiple crypto
toolkits each do their own separate thing. Because some toolkits haven't
offered a complete solution, some applications have used their own
solutions on top of them.

We cannot solve all of that at once. We must start with a first step.
This first step is to create a common infrastructure. Once that common
infrastructure is ready, then applications can start to use it.

After that initial step has been completed, we can advertise it and
recommend that new applications use it. And we can start investigating
existing applications and work with maintainers to get them changed to
the use new shared infrastructure.

The goal for this initial round is to have the shared infrastructure
ready, and to offer a default functionality that applications are able
to use.

Kai




More information about the devel mailing list