From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.devel Subject: Re: NSM certificate prompt Date: Fri, 19 Dec 2014 23:37:19 +0200 Message-ID: <83ppbfs4mo.fsf@gnu.org> References: <83a92r625n.fsf@gnu.org> <87wq5vefiz.fsf@gmx.de> <83388j5wrs.fsf@gnu.org> <87mw6reaxu.fsf@gmx.de> <83y4qb4eeg.fsf@gnu.org> <83vblf4b2p.fsf@gnu.org> <87r3w3z60b.fsf@lifelogs.com> <83r3w348m8.fsf@gnu.org> <87iohfyprn.fsf@lifelogs.com> <83mw6q51x4.fsf@gnu.org> <83k31u43qm.fsf@gnu.org> <87d27fj0p0.fsf@building.gnus.org> Reply-To: Eli Zaretskii NNTP-Posting-Host: plane.gmane.org X-Trace: ger.gmane.org 1419025079 4864 80.91.229.3 (19 Dec 2014 21:37:59 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Fri, 19 Dec 2014 21:37:59 +0000 (UTC) Cc: larsi@gnus.org, emacs-devel@gnu.org To: Simon Leinen Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Fri Dec 19 22:37:52 2014 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1Y25F7-0002jY-Su for ged-emacs-devel@m.gmane.org; Fri, 19 Dec 2014 22:37:50 +0100 Original-Received: from localhost ([::1]:60630 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y25F6-00029U-Sq for ged-emacs-devel@m.gmane.org; Fri, 19 Dec 2014 16:37:48 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:44055) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y25Em-000253-2O for emacs-devel@gnu.org; Fri, 19 Dec 2014 16:37:33 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Y25Eg-000389-8f for emacs-devel@gnu.org; Fri, 19 Dec 2014 16:37:28 -0500 Original-Received: from mtaout28.012.net.il ([80.179.55.184]:54822) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y25Eg-000381-0p for emacs-devel@gnu.org; Fri, 19 Dec 2014 16:37:22 -0500 Original-Received: from conversion-daemon.mtaout28.012.net.il by mtaout28.012.net.il (HyperSendmail v2007.08) id <0NGU00F00M2UJN00@mtaout28.012.net.il> for emacs-devel@gnu.org; Fri, 19 Dec 2014 23:35:05 +0200 (IST) Original-Received: from HOME-C4E4A596F7 ([87.69.4.28]) by mtaout28.012.net.il (HyperSendmail v2007.08) with ESMTPA id <0NGU006HUMMH4N90@mtaout28.012.net.il>; Fri, 19 Dec 2014 23:35:05 +0200 (IST) In-reply-to: X-012-Sender: halo1@inter.net.il X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 80.179.55.184 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:180356 Archived-At: > From: Simon Leinen > Date: Fri, 19 Dec 2014 20:53:31 +0100 > Cc: Eli Zaretskii , emacs-devel@gnu.org > > On Fri, Dec 19, 2014 at 1:14 PM, Lars Ingebrigtsen wrote: > > To the best of my knowledge, no other browsers use the system's > > certificates. > > I am forced to use Mac OS X at work. (Yes, I know, I should look for > another job.) All browsers *except* for Firefox do use the system's > certificate store ("Keychain"). This makes it quite convenient for > the user to manage which kinds of certificates she wants to trust. I'd > like Emacs' emerging TLS support to be able to access the same. It already does -- assuming that GnuTLS on OS X reads that store when we call the gnutls_certificate_set_x509_system_trust function. If not, then you should lobby the GnuTLS developers to make GnuTLS do that on OS X.