Re: Bug#1052161: ITP: libmozilla-ca-perl -- Mozilla's CA cert bundle in PEM format

gregor herrmann <[email protected]>
Newsgroups gmane.linux.debian.devel.perl
Message-ID <[email protected]>
On Mon, 18 Sep 2023 17:48:33 +0200, Francesco P. Lovergine wrote:

> > > May I suggest that you ask ftp-masters to REJECT it?

Seems they were quicker :)

> > Yep indeed. Maybe a wrapper could be tought for packages that have some optional dep on that?
> I would simply patch Mozilla::CA to have SSL_ca_file() returning the Debian
> directory /usr/share/ca-certificates/mozilla instead of the cacert.pem file.
> That would avoid to patch third-parties code that eventually use explicitly
> the modules. This is compatible with the IO::Socket::SSL module.

Right, that's a possible option.
 
> Does it make sense?

Given that we've had to patch only 3 packages (in pkg-perl) over the
last decades and that the patch is trivial¹, and given that a
Mozilla::CA package doing different things on Debian than upstream
would cause confusion, I recommend against going that way.

Let's see what others on the list say.


Cheers,
gregor


¹ modulo grep errors:
liblwp-protocol-https-perl/debian/patches/cert.patch
liblwpx-paranoidagent-perl/debian/patches/0002-Use-ca-certificates.patch
libnet-jabber-bot-perl/debian/patches/2001_cert.patch

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmUItqtfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgYqHhAAha/8dKWGbKtSyYtmxQ1ACexjJ+9dIbqwLb28urnt54ISh12DkXRR8XHu
kZxqKP8deGzkQSDoJGKLVFWpElYgcieDDWWJPYO5SEOyfy6u23paFruZgEiX/PP9
ZteWHiZ5296nr75zlXlJQEyud+0TuTXlDyfFUN484pagBmQP0sD5sc9FeKP7heIi
8MyqN+5EYBKBTWd0j2dyDE6wYThqVY7X0fKDfGjy81dlihKdjvqUQLuoLqFvyuZ4
26/blENgffY74MyCwbDk2A7Jd5mNaJqm7VHNW8EWBkAFoHJp7NJhv1YD/465IM2N
NiTxxmqsHtpw9DWneQuLKH1li3IUJn/jTeLs+JDywG4sUVSUrg5Nn8J5CAU4aVuu
1hb3wnsZGx9WgwKt/HIfYRYY9Pc/kXJKPtOjzPrVZZYm+Cms5oiObZIN3hLelPJJ
ahuSYammL5OBI+3t5/mvama/BH0DTSHOFiZR41KtxWXxwElg2sFfJetBLY4Ma/d9
0e7mOWXy4lqBRebkMNz6CicrcEd61wNh990DGs7sfv5vSee8flGaJfEdGWcUxbia
J+/iw7ew7Jyh6LNTT66j95EEdJiw3GHE7uO4/HIMM3/46ydWL4xoHb/vBz+fDVvQ
kZISXV+W2yV+qIdL7+ZuDaF2CtsXhSr4b0W7SHm9SDk8/FJWpNM=
=vYsD
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.