From mboxrd@z Thu Jan 1 00:00:00 1970 From: Andreas Enge Subject: Re: Openssl and certificate directory Date: Sun, 8 Feb 2015 10:49:37 +0100 Message-ID: <20150208094937.GA10816@debian> References: <20150207151748.GA6943@debian> <874mqx2mib.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:49634) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YKOVV-0003BO-Cr for guix-devel@gnu.org; Sun, 08 Feb 2015 04:50:26 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1YKOVQ-0007Sj-8i for guix-devel@gnu.org; Sun, 08 Feb 2015 04:50:25 -0500 Received: from mout.kundenserver.de ([212.227.17.13]:58760) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YKOVQ-0007SZ-06 for guix-devel@gnu.org; Sun, 08 Feb 2015 04:50:20 -0500 Content-Disposition: inline In-Reply-To: <874mqx2mib.fsf@netris.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org To: Mark H Weaver Cc: guix-devel@gnu.org On Sat, Feb 07, 2015 at 08:57:32PM -0500, Mark H Weaver wrote: > Unlike GnuTLS, OpenSSL supports setting the trust store location using > environment variables, specifically SSL_CERT_DIR and SSL_CERT_FILE. > Shouldn't we just use those? I had read about these, but the documentation mentions them only in the context of c_rehash. So I thought they were not generally applicable. But indeed they are, I just tried SSL_CERT_DIR with youtube-dl. Also, it can be a ":" separated list of directories. So we should probably encourage its usage by defining a search path with our (future) certificate packages. > If we were to apply this patch, I'd rather have just one rebuild rather > than two, especially since our MIPS build slave is unable to keep up as > it is. What do you think? So maybe we do not need it at all? What do you think? Concerning the rebuilds, I would say that the aim of continuous integration would be to determine exactly the place where something goes wrong, so in general, I am rather in favour of more rebuilds. As the one mips machine cannot keep up, it would then be reasonable to abort earlier builds. Andreas