Re: Can we deprecate NSS signtool?

Kyle Hamilton <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAPMEXDaDM4pnU+hCcC1Ymj1pX1LQK3sD8F3jBLF4kNeLsiOzUw@mail.gmail.com>
http://docs.oracle.com/javase/7/docs/technotes/tools/windows/jarsigner.html

It is probably not as complicated to change the default in a compatible way
as you think.

However, I don't know if anyone still uses signtool.

-Kyle H



On Mon, Jul 3, 2017 at 4:49 AM, Kai Engert <[email protected]> wrote:

> The NSS utility "signtool" is hardcoded to use SHA1 when creating a digital
> signature.
>
> As I've described in this bug:
>   https://bugzilla.mozilla.org/show_bug.cgi?id=1345528
> it might be complicated to change the default to a more secure hash
> algorithm in
> a compatible way.
>
> I wonder who still depends on signtool. If you know, could you please give
> feedback?
>
> I see that OpenJDK ships its own tool, jarsigner.
>
> Mozilla appears to use different tools to sign the Firefox addons in XPI
> file
> format, using python. Franziskus pointed me to:
>   https://github.com/mozilla-services/autograph/pull/46 )
>
> Can we declare signtool as deprecated?
>
> Thanks
> Kai
>
> --
> dev-tech-crypto mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-tech-crypto
>
-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.