Re: [spice-gtk] Use system-wide trust certificate store

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, Sep 18, 2013 at 03:01:56PM +0200, Marc-André Lureau wrote:
> On Wed, Sep 18, 2013 at 2:40 PM, Christophe Fergeau <cfergeau@xxxxxxxxxx> wrote:
> > Currently, spice-gtk will look in $HOME/.spicec/spice_truststore.pem
> > by default for its trust certificate store (to verify the certificates
> > used during SPICE TLS connections). However, these days a system-wide
> > trust store can be found in /etc/pki or /etc/ssl.
> > This commit checks at compile time where the trust store is located,
> > and then loads it before loading the user-specified trust store.
> > This can be disabled at compile time using --without-ca-certificates.
> 
> Is it really a good idea to "guess" the location of the trust store?

This is how it's done in glib-networking, imo it's fine, I don't really
see someone deciding to put a in /etc/pki or /etc/ssl with a generic name
and then complaining that this had side effects.

Christophe

Attachment: pgpCNG6v7HomB.pgp
Description: PGP signature

_______________________________________________
Spice-devel mailing list
Spice-devel@xxxxxxxxxxxxxxxxxxxxx
http://lists.freedesktop.org/mailman/listinfo/spice-devel

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]     [Monitors]