From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0 Subject: Re: [PATCH] gnurl: add CA path to configure-flags Date: Sun, 12 Jun 2016 15:56:22 +0000 Message-ID: <20160612155622.GB26362@khazad-dum> References: <20160611205128.GA23445@khazad-dum> <20160612142215.GA20253@solar> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="St7VIuEGZ6dlpu13" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:50387) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bC7kW-0002HI-GD for guix-devel@gnu.org; Sun, 12 Jun 2016 11:56:33 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bC7kT-0008PG-By for guix-devel@gnu.org; Sun, 12 Jun 2016 11:56:32 -0400 Received: from 93-95-228-168.1984.is ([93.95.228.168]:45663 helo=beleriand.n0.is) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bC7kS-0008PB-Vf for guix-devel@gnu.org; Sun, 12 Jun 2016 11:56:29 -0400 Received: by beleriand.n0.is (OpenSMTPD) with ESMTPSA id 9556b4b3 TLS version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO for ; Sun, 12 Jun 2016 15:56:25 +0000 (UTC) Content-Disposition: inline In-Reply-To: <20160612142215.GA20253@solar> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org --St7VIuEGZ6dlpu13 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2016-06-12(04:22:15+0200), Andreas Enge wrote: > Hello, > > On Sat, Jun 11, 2016 at 08:51:28PM +0000, ng0 wrote: > > * gnurl(configure-flags): --with-ca-path=3D/etc/ssl/certs/ > > my impression is that this absolute path does not do what we would like > it to. Optimally, the user would decide, by installing a certificate bund= le > into the profile, which certificates to use. And on a foreign distro, the > random certificate bundle in /etc/ssl/certs, which does not come from Gui= x, > would be used by the Guix gnurl, which would be surprising. > > Andreas It is not entirely clear to me anymore why this was suggested to me in the past 4 months. I am aware of the differences, so maybe this could point to where ever the /ssl/certs/ are? When you know that gnurl does not need this, we're all good without this change. Gnurl so far is just curl with some project recommended build switches, so if guix' curl detects the ssl/certs/ dir, gnurl should too. -- =E2=99=A5=E2=92=B6 ng0 For non-prism friendly talk find me on psyced.org / loupsycedyglgamf.onion --St7VIuEGZ6dlpu13 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- iF4EARYKAAYFAlddhiYACgkQhhoAchyzrCAOcAEA0rHVaWFWqQpisZGUWvu0GdZt KoW8J6+iK4uhtvhpJDsBALqthiayyzGdVdelBOtmiAFf6I03bKqX7RZqcqkuyP8H =PBo3 -----END PGP SIGNATURE----- --St7VIuEGZ6dlpu13--