Re: Official code signing certificate

2013-05-26 Thread janI
On 26 May 2013 09:53, Mechtilde wrote: > Hello Andrea, > > Am 26.05.2013 00:07, schrieb Andrea Pescetti: > > janI wrote: > >> in all fairness jsc and rob have worked with this for over a > >> year, so it would be more fair to have them do it, and I do not want to > >> come "in between". > > > > T

Re: Official code signing certificate

2013-05-26 Thread Mechtilde
Hello Andrea, Am 26.05.2013 00:07, schrieb Andrea Pescetti: > janI wrote: >> in all fairness jsc and rob have worked with this for over a >> year, so it would be more fair to have them do it, and I do not want to >> come "in between". > > This is a good summary written by Juergen: > http://wiki.a

Re: Official code signing certificate

2013-05-25 Thread Andrea Pescetti
janI wrote: in all fairness jsc and rob have worked with this for over a year, so it would be more fair to have them do it, and I do not want to come "in between". This is a good summary written by Juergen: http://wiki.apache.org/general/ASFCodeSigning Note that at FOSDEM we were (inconclusive

Re: Official code signing certificate

2013-05-25 Thread janI
; >> > >> >> On Fri, May 24, 2013 at 5:21 PM, Rob Weir > wrote: > >> >>> On Fri, May 24, 2013 at 5:01 PM, janI wrote: > >> >>>> On 24 May 2013 22:30, Juergen Schmidt > wrote: > >> >>>> > >> >>>&g

Re: Official code signing certificate

2013-05-25 Thread Rob Weir
;>>>> (as >> >>>>>> I did today on IRC) if we do not formulate our requirements very >> clearly. >> >>>>>> >> >>>>>> >> >>>>> >> >>>>> decisions are made on mailing li

Re: Official code signing certificate

2013-05-25 Thread janI
On 25 May 2013 18:01, Mechtilde wrote: > Hello Jan, > > can you give me a short description what we/you need and what are the > problems with apache infrastructure. > I could, but in all fairness jsc and rob have worked with this for over a year, so it would be more fair to have them do it, and

Re: Official code signing certificate

2013-05-25 Thread janI
> Apache, what not happened on a mailing list, is not relevant ;-) > >>>>> Well it seems that infra is always special. > >>>>> I tried several times to discuss it on the infra mailing list and I > >>>>> believe I have described ver

Re: Official code signing certificate

2013-05-25 Thread Rob Weir
e would have a cert. I also proposed a solution that >>>>> can >>>>> work from my point of view and I started to collect the info on a wiki >>>>> page >>>>> as suggested. >>>>> There might be other solutions to do it but I ha

Re: Official code signing certificate

2013-05-25 Thread Mechtilde
Hello Jan, can you give me a short description what we/you need and what are the problems with apache infrastructure. I'm not so familar with the apache infrastructure to understand all things of the thread. Then I will give this information to people who are familar with organisation assurance

Re: Official code signing certificate

2013-05-25 Thread janI
On 25 May 2013 15:31, Mechtilde wrote: > Hello, > > what about an organisation assurance by Cacert. > > At FOSDEM 2013 there are some discussions with people from cacert. > > If you need more informations and contacts I will act as an agent. > If you can get some information, I would like to read

Re: Official code signing certificate

2013-05-25 Thread Mechtilde
Hello, what about an organisation assurance by Cacert. At FOSDEM 2013 there are some discussions with people from cacert. If you need more informations and contacts I will act as an agent. Let me know Kind regards Mechtilde Am 25.05.2013 15:22, schrieb janI: > On 25 May 2013 12:04, Andrea P

Re: Official code signing certificate

2013-05-25 Thread janI
On 25 May 2013 12:04, Andrea Pescetti wrote: > Dave Fisher wrote: > >> The main concern that the ASF has with digitally signing with a >> singular apache.org certificate for the whole foundation is keeping >> it in strict control. For some this means physical machines. This is >> a high bar. >> I

Re: Official code signing certificate

2013-05-25 Thread Andrea Pescetti
Dave Fisher wrote: The main concern that the ASF has with digitally signing with a singular apache.org certificate for the whole foundation is keeping it in strict control. For some this means physical machines. This is a high bar. I wonder if the ASF would allow AOO to experiment with an OpenOff

Re: Official code signing certificate

2013-05-24 Thread Dave Fisher
ert. I also proposed a solution that can >>>> work from my point of view and I started to collect the info on a wiki page >>>> as suggested. >>>> There might be other solutions to do it but I have no in place and nobody >>>> convinced me that my prop

Re: Official code signing certificate

2013-05-24 Thread Rob Weir
t; There might be other solutions to do it but I have no in place and nobody >>> convinced me that my proposed approach can not work. >>> I agree that it's not easy and I simply have no energy to discuss further >>> at the moment. I have enough other thing

Re: Official code signing certificate

2013-05-24 Thread Rob Weir
I simply have no energy to discuss further >> at the moment. I have enough other things to do. >> >> Juergen >> > >> > rgds >> > jan I. >> > >> > -- Forwarded message -- >> > From: Scott Deboy >> > Dat

Re: Official code signing certificate

2013-05-24 Thread janI
n I. > > > > -- Forwarded message -- > > From: Scott Deboy > > Date: 24 May 2013 18:59 > > Subject: Re: Official code signing certificate > > To: infrastructure-...@apache.org > > > > > > Logging Services has a simple requirement

Re: Official code signing certificate

2013-05-24 Thread Juergen Schmidt
I simply have no energy to discuss further at the moment. I have enough other things to do. Juergen > > rgds > jan I. > > -- Forwarded message -- > From: Scott Deboy > Date: 24 May 2013 18:59 > Subject: Re: Official code signing certificate > To: infr

Re: Official code signing certificate

2013-05-24 Thread Rob Weir
nclear to Infra? We've been discussing this for more than a year now, so I'd be surprised if there are any technological questions remaining at this point. -Rob > rgds > jan I. > > -- Forwarded message -- > From: Scott Deboy > Date: 24 May 2013

Fwd: Official code signing certificate

2013-05-24 Thread janI
Hi. we are not alone in ASF wishing code signing, but we might get run over (as I did today on IRC) if we do not formulate our requirements very clearly. rgds jan I. -- Forwarded message -- From: Scott Deboy Date: 24 May 2013 18:59 Subject: Re: Official code signing certificate