RFC: Signed JAR Packaging Policy

Matthew Miller mattdm at mattdm.org
Mon Mar 12 21:02:06 UTC 2007


On Mon, Mar 12, 2007 at 04:57:45PM -0400, Warren Togami wrote:
> Why this is bad?
> It still is not fully reproducible in a sense that other people can't 
> take our source, modify it slightly, and make a Sun-blessed JSS JAR.

I'm really against it. At the very least, it screws over CentOS. This a bad
path to be going down. 

I'd much prefer gcj and the future Fedora-shipped implementation of the Sun
JVM to make it easy to use self-generated certificates. If someone wants to
install a proprietary JVM, let's make _that_ the hard case.


> - This promotes the spirit of FOSS's ideals without compromising on 
> those ideals.

Except it doesn't, and it doesn't.

-- 
Matthew Miller           mattdm at mattdm.org          <http://mattdm.org/>
Boston University Linux      ------>              <http://linux.bu.edu/>




More information about the Fedora-maintainers mailing list