Changes between Version 1 and Version 2 of Signing
- Timestamp:
- 11/05/15 10:54:47 (9 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Signing
v1 v2 1 General Topics in Public Key Infrastructure (PKI) for OSGeo.org 1 = General Topics in Public Key Infrastructure (PKI) for OSGeo.org = 2 2 3 General Discussion 3 == General Discussion == 4 4 5 OSGeo Board has passed a motion to allocate $500 to certificate acquisition6 5 7 http://lists.osgeo.org/pipermail/board/2015-October/013321.html 6 '''Anita Graser''' and the '''QGis Team''' are interested in signing binaries 8 7 9 Anita Graser has expressed interest in the initiative 8 jgarnett proposed a motion at the Board level (also represents Boundless community outreach); Michael Smith supports; Sanghee Shin, Jorge Sanz supporting 10 9 11 jgarnett proposed a motion at the Board level (also represents Boundless community outreach); Michael Smith seconds; Sanghee Shin, Jorge Sanz supporting 10 * http://lists.osgeo.org/pipermail/board/2015-October/013445.html 12 11 13 darkblue_b proposed participating in the EFF/Mozilla Foundation Let's Encrypt initiative, and generally be modern in setting up server infrastructure for a FOSS dot-org. This prompted an investigation into the acquisition and use of Public Key Infrastructure (PKI) x.509 certificates, a heirarchical trust authority structure, and this wiki page.12 '''darkblue_b''' proposed participating in the EFF/Mozilla Foundation Let's Encrypt initiative, and generally be modern in setting up server infrastructure for a FOSS dot-org. This prompted an investigation into the acquisition and use of Public Key Infrastructure (PKI) x.509 certificates (a heirarchical trust authority structure), Debian-style package signing, and this wiki page. 14 13 15 wildintellect (current SAC chair) in favor of getting SSL certs for all our websites, if some of those are the Free ones from that initiativethat is fine14 '''wildintellect''' (current SAC chair) in favor of getting SSL certs for all our websites, if some of those are the Free ones from the Lets Encrypt initiative, that is fine 16 15 17 evenR suggests 16 '''evenR''' points to: 18 17 https://fedoraproject.org/wiki/ReleaseEngineering/Projects/SigningServer 19 18 20 the QGis team is interested in Signing Binaries for Mac and Windows 19 '''Larry Shaffer''' joins SAC for the purposes of this project 21 20 22 Larry Shaffer is involved in signing binaries, and is working with jgarnett 21 '''nhv''' is observing 23 22 24 nhv is observing the process 25 26 * Signing Binaries based on the Debian Model 23 == Signing Binaries based on the Debian Model 27 24 28 25 A .dsc file shows some important parts.. checksum on certain things, a name of a person, and lastly the GnuPG PGP Signature … … 31 28 (.dsc) in that text file are checksums, the name of a person, and a GNU PGP signature.. 32 29 33 *Signing Binaries on the LocationTech model30 == Signing Binaries on the LocationTech model 34 31 35 32 LocationTech says in their handbook … … 43 40 44 41 45 *HTTPS using Lets Encrypt42 == HTTPS using Lets Encrypt 46 43 47 darkblue_b sez' Board Members, List Members, all - 44 '''darkblue_b''' sez' 45 Board Members, List Members, all - 48 46 49 47 Today I asked Yuvi Panda, lead dev at Wikimedia Labs, a … … 61 59 FSF isn't a CA and I don't think they have any intention of being one 62 60 61 -- 63 62 64 63 65 * Generating Internal Certificates with openssl 64 {{{ 65 66 Date: Tue, 03 Nov 2015 10:54:01 -0800 67 From: Brian M Hamlin <maplabs@light42.com> 68 Reply-To: Brian M Hamlin <maplabs@light42.com> 69 Subject: Re: Let's Encrypt 70 To: Seth David Schoen <schoen@eff.org> 71 Cc: larrys@dakotacarto.com 72 73 Hi Seth - 74 75 76 77 I wrote to Peter very shortly after our email exchange, but I have not heard anything back. 78 79 Basically, I can sum up our inquiry this way -- 80 81 82 83 * OSGeo.org wants to participate in Let's Encrypt 84 85 * OSGeo.org may want to purchase PKI certificates from a Certificate Authority, to sign binaries for WIndows and Mac 86 87 which CA to choose ? 88 89 * in general, PKI certificates in line with your current thinking while we setup some new servers (mainly at OSUOSL) 90 91 92 93 thanks --Brian 94 95 96 97 On Tue, 20 Oct 2015 11:19:23 -0700, Seth David Schoen <schoen@eff.org> wrote: 98 99 Hi Brian, 100 101 Thanks for your interest in Let's Encrypt! I'm on sabbatical so you 102 should probably try Peter Eckersley <pde@eff.org> if you have further 103 questions. 104 105 I hope Let's Encrypt can be useful to OSGeo, but in answer to your 106 question, we're planning to do only TLS server certificates and not 107 any other kind of certificate (for example, we're not planning to 108 offer code signing certificates). All of our certificates will be 109 Domain Validation only and will be free of charge. They should be 110 available to the public during the week of November 21, and there's 111 a beta program now that's going to be issuing live certificates to 112 users before then. It should still be possible to join the beta, 113 but I can't guarantee how soon before general availability you would 114 end up getting access (it might even turn out to be around the time 115 of general availability). 116 117 -- 118 Seth Schoen <schoen@eff.org> 119 Senior Staff Technologist https://www.eff.org/ 120 Electronic Frontier Foundation https://www.eff.org/join 121 815 Eddy Street, San Francisco, CA 94109 +1 415 436 9333 x107 122 123 124 125 126 -- 127 Brian M Hamlin 128 OSGeo California Chapter 129 blog.light42.com 130 131 }}} 132 133 134 135 136