Control: tags -1 + wontfix On Mon, 2015-12-21 at 10:23 +0100, Thijs Kinkhorst wrote: > Such polarizing comments are not welcome and do not serve to improve > Debian. I'm closing the bug now. I'm afraid when factual issues are considered polarising. Well serving examples for such CA's should include e.g. CNNIC or TURKTRUST (yeah, of course, it was an "accident" that they created forged google.com certs and placed them in the wild o.O)
> Please refrain from posting new bugs as > long as you intend to include statements that accuse colleague > developers > of corruption. Uhm, if you read closely, I haven't accused anyone of corruption, neither specific developers, not even Mozilla, even though what the later does is morally probably not that much better - but everyone has to decide this for himself. What I wrote was, that "any CA is included for money", and AFAIU, this is the actual way: a CA needs to get some organisation having an audit done, which in turn it pays for. The worth of the audits in turn, was e.g. shown in the DigiNotar or again TURKTRUST cases. CAs in turn typically earn their money (and lots more) back by selling certificates. So I'm afraid you consider my comments polarising, but it wasn't me who made the system as it is. Further, I would enjoy if you wouldn't ready any statements of mine between the lines which there aren't written. Maybe words weren't clear enough as I'm no native English speaker, but before accusing me of allegedly accusing some "colleague developers" of corruption, it would have been perhaps not so inappropriate to ask whether this is meant or not. > We will welcome any factual bug reports As for the enhancement request itself, it may be acceptable for you to have CAs included which, by accident or not, release forged certificates - other Debian users may however not desire this. I read the closing of the bug, based on my motivation text why it makes sense for improving the listing of ca-certificates debconf selection dialogue, that such change is not desired. Therefore, I think, the bug should additionally be marked wontfix, please correct me if wrong. Cheers, Chris.
smime.p7s
Description: S/MIME cryptographic signature

