I have a promising GSoC candidate who is interested in working on bug
1162897 (RFC7512 URI support¹), and potentially also on bug 248722
(honour the system-wide configuration for PKCs#11 modules, when it
exists²).

I am more than happy to co-mentor, but I think it *really* needs a
proper NSS developer to be the primary mentor. Could I interest anyone
in helping out, please?

This is a really useful project. Applications built against OpenSSL or
GnuTLS will transparently load the PKCS#11 tokens specified by the
system configuration, and allow objects therein to be identified by
their PKCS#11 URI. This consistency is a Good Thing™, and the Fedora
distribution at least has explicit packaging guidelines that its
packages SHOULD behave this way.

So Fedora has open bugs against its curl package, for example, which
could *only* be resolved right now by building curl against GnuTLS
instead of NSS.

This is obviously not the ideal solution; let's make NSS play nicely
too :)

-- 
David Woodhouse                            Open Source Technology Centre
david.woodho...@intel.com                              Intel Corporation


¹ https://bugzilla.mozilla.org/show_bug.cgi?id=1162897
² https://bugzilla.mozilla.org/show_bug.cgi?id=248722

Attachment: smime.p7s
Description: S/MIME cryptographic signature

-- 
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to