Re: [gentoo-dev] SSL certificates in binary packages

2007-08-22 Thread Natanael Copa
On Wed, 2007-08-22 at 13:29 +0200, Raphael Marichez wrote: > On Tue, 21 Aug 2007, Natanael Copa wrote: > > > Hi, > > > > I use the gentoo framework to build binary packages. I noticed that most > > packages creates the ssl certificate during src_install(). This makes > > all binary packages conta

Re: [gentoo-dev] SSL certificates in binary packages

2007-08-22 Thread Raphael Marichez
On Tue, 21 Aug 2007, Natanael Copa wrote: > Hi, > > I use the gentoo framework to build binary packages. I noticed that most > packages creates the ssl certificate during src_install(). This makes > all binary packages contain the ssl certs which is a security threat. Hi, If you are really con

Re: [gentoo-dev] SSL certificates in binary packages

2007-08-21 Thread Mike Frysinger
On Tuesday 21 August 2007, Robin H. Johnson wrote: > On Tue, Aug 21, 2007 at 04:12:32PM +0200, Natanael Copa wrote: > > I use the gentoo framework to build binary packages. I noticed that most > > packages creates the ssl certificate during src_install(). This makes > > all binary packages contain

Re: [gentoo-dev] SSL certificates in binary packages

2007-08-21 Thread Robin H. Johnson
On Tue, Aug 21, 2007 at 04:12:32PM +0200, Natanael Copa wrote: > I use the gentoo framework to build binary packages. I noticed that most > packages creates the ssl certificate during src_install(). This makes > all binary packages contain the ssl certs which is a security threat. I filed bug #1747

Re: [gentoo-dev] SSL certificates in binary packages

2007-08-21 Thread Alec Warner
On 8/21/07, Natanael Copa <[EMAIL PROTECTED]> wrote: > Hi, > > I use the gentoo framework to build binary packages. I noticed that most > packages creates the ssl certificate during src_install(). This makes > all binary packages contain the ssl certs which is a security threat. > > The net-nds/ope

[gentoo-dev] SSL certificates in binary packages

2007-08-21 Thread Natanael Copa
Hi, I use the gentoo framework to build binary packages. I noticed that most packages creates the ssl certificate during src_install(). This makes all binary packages contain the ssl certs which is a security threat. The net-nds/openldap package has understood this and calls docert from pkg_posti