User Details
User Details
- User Since
- Feb 25 2025, 4:54 PM (58 w, 4 d)
- Roles
- Disabled
Apr 25 2025
Apr 25 2025
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
Apr 7 2025
Apr 7 2025
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
Apr 5 2025
Apr 5 2025
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
Feb 26 2025
Feb 26 2025
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
As for these:
- composer: I have patched it upstream, it just works for months now
- rust (cargo): I have a patch here and waiting for a upstream and downstream: https://reviews.freebsd.org/D49120
- pip: it works, what does not work with base?
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
I think this should not intervene with ca_root_nss for the time being and should be changed to -f
Feb 25 2025
Feb 25 2025
• heliosyne_gmail.com added a comment to D49130: certctl: Add support for generating a certificate bundle (CAfile).
I'm the originator of patch. I'll try to answer specific questions, but all the discussion of which paths are correct is somewhat moot. Some of it was already hashed out in the PR, but in short, hier(7) and the general base vs local engineering fence means /etc/ssl/certs and /etc/ssl/cert.pem are probably the best choices for canonical locations managed by a base program.
