Re: RFC: Signed JAR Packaging Policy

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Jesse Keating wrote:

I'd much prefer gcj and the future Fedora-shipped implementation of the Sun
JVM to make it easy to use self-generated certificates. If someone wants to
install a proprietary JVM, let's make _that_ the hard case.

I agree. How much fun would it be if apache suddenly decided to not function with self signed certs and any cert you used had to come from verasign ?


Hmm, CentOS is a good counter argument.

I guess, we don't have any way of shipping a signed JAR in Fedora.

The best we can do is to ship an unsigned JAR and make all FOSS software not require the signature (because we relied on the RPM sig instead). If others want to provide a parallel install signed JAR RPM for arbitrary 3rd party software to use, that is their decision.

Warren Togami
wtogami@xxxxxxxxxx

--
Fedora-maintainers mailing list
Fedora-maintainers@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-maintainers

--
Fedora-maintainers-readonly mailing list
Fedora-maintainers-readonly@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-maintainers-readonly

[Index of Archives]     [Fedora Users]     [Fedora Development]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]

  Powered by Linux