emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Patch] Make tls.el support certificate verification


From: Elias Oltmanns
Subject: Re: [Patch] Make tls.el support certificate verification
Date: Sun, 25 Nov 2007 01:35:08 +0100
User-agent: Gnus/5.110007 (No Gnus v0.7)

Reiner Steib <address@hidden> wrote:
[...]
> Some remarks for future contributions:
[...]

Thanks for those hints.

>
> See http://article.gmane.org/gmane.emacs.gnus.commits/5529 for my
> cosmetic/style changes.

Unfortunately, this link seems to be a dead end.

>
> Would it be useful to add the strings suggested in the doc string of
> `tls-checktrust' to `tls-program'?  Or provide them as custom options
> for `tls-program'?

Well, I wasn't quite sure about it at the time and I'm not any wiser
yet.  I'm using the examples given in the doc string in a Debian
environment but they need not work properly for other distributions or
OSes.  In fact, I think it is so hard to come up with sensible default
values that are actually worth making the effort that the best GNU
developers can do is to provide the facilities and sufficient
documentation to make use of them.  Distributors may or may not tweak
the default settings and give further advice to their users but even
they shouldn't enable tls-checktrust by default as this really should be
a decision consciously taken by the end user.  After all, the mail
server needn't have a certificate signed by one of the well known CAs
and may still be valid.  Besides, users might want to specify the set of
trusted root certificates depending on the server emacs is connecting
to.  All this seems to make proper documentation more important than
presetting any defaults.  Do you think the provided doc strings can
serve this purpose or should I squeeze in a few sentences somewhere
else?

Regards,

Elias





reply via email to

[Prev in Thread] Current Thread [Next in Thread]