Re: ca-certificates 2014.2.1 will remove several still valid CA certificates with weak keys

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 2014-09-17 at 14:16 +0200, Kai Engert wrote:
> I think it's good that we have started experimenting with these
> removals
> in the testing areas of Fedora, because it raises awareness of these
> issues, and hopefully can bring higher priority to getting OpenSSL and
> GnuTLS enhanced.
> 
> But given the heavy complaints, maybe it's necessary that we delay
> shipping the upstream removals into stable Fedora a little longer,
> until
> we have a better solution (either by having OpenSSL/GnuTLS enhanced,

Sounds good. Thanks for taking this issue seriously!

>  or
> maybe by implementing a way that enables users/admins to re-enable
> legacy CA certificates).

For the purposes of Fedora Workstation, no user intervention should be
required.

Michael

Attachment: signature.asc
Description: This is a digitally signed message part

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux