| Summary: | TDE should use system SSL certificates instead of now rather elderly ex-KDE bundle (patch) | ||
|---|---|---|---|
| Product: | TDE | Reporter: | Nick Leverton <nick> |
| Component: | tdelibs | Assignee: | Timothy Pearson <kb9vqf> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | bmsass, bugwatch, kb9vqf |
| Priority: | P5 | ||
| Version: | 3.5.13 [Trinity] | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Compiler Version: | TDE Version String: | ||
| Application Version: | Application Name: | ||
| Attachments: | Patch for Debian KDE4, something very similar should fit Trinity | ||
|
Description
Nick Leverton
2012-07-14 14:12:31 CDT
(In reply to comment #0) > As an experiment I symlinked /etc/ssl/certs/ca-certificates.crt from Debian > Testing in place of /opt/trinity/share/apps/kssl/ca-bundle.crt, and all the > sites that used to give "unknown signing authority" warnings now validate > perfectly. Is there any reason not to do that in the packaging (by shipping a symlink instead of ca-bundle.crt)? (In reply to comment #1) > (In reply to comment #0) > > As an experiment I symlinked /etc/ssl/certs/ca-certificates.crt from Debian > > Testing in place of /opt/trinity/share/apps/kssl/ca-bundle.crt, and all the > > sites that used to give "unknown signing authority" warnings now validate > > perfectly. > > Is there any reason not to do that in the packaging (by shipping a symlink > instead of ca-bundle.crt)? Not that I am aware of. Yup, that's what the Debian KDE team have done. I haven't had time to review the attached patch and update to TDE but it is a pretty simple packaging change. Fixed in GIT hash 82fe514 (tde-packaging). Thanks for reporting, and for the suggested solution! |