Changes between Version 1 and Version 2 of Signing


Ignore:
Timestamp:
Nov 5, 2015, 10:54:47 AM (9 years ago)
Author:
darkblueb
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • Signing

    v1 v2  
    1 General Topics in Public Key Infrastructure (PKI) for OSGeo.org
     1= General Topics in Public Key Infrastructure (PKI) for OSGeo.org =
    22
    3 General Discussion
     3== General Discussion ==
    44
    5 OSGeo Board has passed a motion to allocate $500 to certificate acquisition
    65
    7 http://lists.osgeo.org/pipermail/board/2015-October/013321.html
     6'''Anita Graser''' and the '''QGis Team''' are interested in signing binaries
    87
    9 Anita Graser has expressed interest in the initiative
     8jgarnett  proposed a motion at the Board level (also represents Boundless community outreach); Michael Smith supports; Sanghee Shin, Jorge Sanz supporting
    109
    11 jgarnett  proposed a motion at the Board level (also represents Boundless community outreach); Michael Smith seconds; Sanghee Shin, Jorge Sanz supporting
     10*  http://lists.osgeo.org/pipermail/board/2015-October/013445.html
    1211
    13 darkblue_b proposed participating in the EFF/Mozilla Foundation Let's Encrypt initiative, and generally be modern in setting up server infrastructure for a FOSS dot-org. This prompted an investigation into the acquisition and use of Public Key Infrastructure (PKI) x.509 certificates, a heirarchical trust authority structure, and this wiki page.
     12'''darkblue_b''' proposed participating in the EFF/Mozilla Foundation Let's Encrypt initiative, and generally be modern in setting up server infrastructure for a FOSS dot-org. This prompted an investigation into the acquisition and use of Public Key Infrastructure (PKI) x.509 certificates (a heirarchical trust authority structure), Debian-style package signing, and this wiki page.
    1413
    15 wildintellect (current SAC chair) in favor of getting SSL certs for all our websites, if some of those are the Free ones from that initiative that is fine
     14'''wildintellect''' (current SAC chair) in favor of getting SSL certs for all our websites, if some of those are the Free ones from the Lets Encrypt initiative, that is fine
    1615
    17 evenR suggests
     16'''evenR''' points to:
    1817  https://fedoraproject.org/wiki/ReleaseEngineering/Projects/SigningServer
    1918
    20 the QGis team is interested in Signing Binaries for Mac and Windows
     19'''Larry Shaffer''' joins SAC for the purposes of this project
    2120
    22 Larry Shaffer is involved in signing binaries, and is working with jgarnett
     21'''nhv''' is observing
    2322
    24 nhv is observing the process
    25 
    26 * Signing Binaries based on the Debian Model
     23== Signing Binaries based on the Debian Model
    2724
    2825A .dsc file shows some important parts.. checksum on certain things, a name of a person, and lastly the GnuPG PGP Signature
     
    3128(.dsc)  in that text file are checksums, the name of a person, and a GNU PGP signature..
    3229
    33 * Signing Binaries on the LocationTech model
     30== Signing Binaries on the LocationTech model
    3431
    3532LocationTech says in their handbook
     
    4340
    4441
    45 * HTTPS using Lets Encrypt
     42== HTTPS using Lets Encrypt
    4643
    47 darkblue_b sez'  Board Members, List Members, all -
     44'''darkblue_b''' sez' 
     45  Board Members, List Members, all -
    4846
    4947  Today I asked Yuvi Panda, lead dev at Wikimedia Labs, a
     
    6159  FSF isn't a CA and I don't think they have any intention of being one
    6260
     61--
    6362
    6463
    65 * Generating Internal Certificates with openssl
     64{{{
     65
     66Date: Tue, 03 Nov 2015 10:54:01 -0800
     67From: Brian M Hamlin <maplabs@light42.com>
     68Reply-To: Brian M Hamlin <maplabs@light42.com>
     69Subject: Re: Let's Encrypt
     70To: Seth David Schoen <schoen@eff.org>
     71Cc: larrys@dakotacarto.com
     72
     73Hi Seth -
     74
     75 
     76
     77  I wrote to Peter very shortly after our email exchange, but I have not heard anything back.
     78
     79Basically, I can sum up our inquiry this way --
     80
     81 
     82
     83  * OSGeo.org wants to participate in  Let's Encrypt
     84
     85  * OSGeo.org may want to purchase PKI certificates from a Certificate Authority, to sign binaries for WIndows and Mac
     86
     87      which CA to choose ?
     88
     89  * in general, PKI certificates in line with your current thinking while we setup some new servers  (mainly at OSUOSL)
     90
     91 
     92
     93thanks --Brian
     94
     95
     96
     97On Tue, 20 Oct 2015 11:19:23 -0700, Seth David Schoen <schoen@eff.org> wrote:
     98
     99    Hi Brian,
     100
     101    Thanks for your interest in Let's Encrypt! I'm on sabbatical so you
     102    should probably try Peter Eckersley <pde@eff.org> if you have further
     103    questions.
     104
     105    I hope Let's Encrypt can be useful to OSGeo, but in answer to your
     106    question, we're planning to do only TLS server certificates and not
     107    any other kind of certificate (for example, we're not planning to
     108    offer code signing certificates). All of our certificates will be
     109    Domain Validation only and will be free of charge. They should be
     110    available to the public during the week of November 21, and there's
     111    a beta program now that's going to be issuing live certificates to
     112    users before then. It should still be possible to join the beta,
     113    but I can't guarantee how soon before general availability you would
     114    end up getting access (it might even turn out to be around the time
     115    of general availability).
     116
     117    --
     118    Seth Schoen <schoen@eff.org>
     119    Senior Staff Technologist https://www.eff.org/
     120    Electronic Frontier Foundation https://www.eff.org/join
     121    815 Eddy Street, San Francisco, CA 94109 +1 415 436 9333 x107
     122
     123
     124
     125
     126--
     127Brian M Hamlin
     128OSGeo California Chapter
     129blog.light42.com
     130
     131}}}
     132
     133
     134
     135
     136