Return-Path: Delivered-To: apmail-directory-dev-archive@www.apache.org Received: (qmail 60174 invoked from network); 13 Jul 2010 13:04:25 -0000 Received: from unknown (HELO mail.apache.org) (140.211.11.3) by 140.211.11.9 with SMTP; 13 Jul 2010 13:04:25 -0000 Received: (qmail 56114 invoked by uid 500); 13 Jul 2010 13:04:25 -0000 Delivered-To: apmail-directory-dev-archive@directory.apache.org Received: (qmail 55916 invoked by uid 500); 13 Jul 2010 13:04:22 -0000 Mailing-List: contact dev-help@directory.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Apache Directory Developers List" Delivered-To: mailing list dev@directory.apache.org Received: (qmail 55907 invoked by uid 99); 13 Jul 2010 13:04:21 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 13 Jul 2010 13:04:21 +0000 X-ASF-Spam-Status: No, hits=2.2 required=10.0 tests=FREEMAIL_FROM,HTML_MESSAGE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of pajbam@gmail.com designates 74.125.82.178 as permitted sender) Received: from [74.125.82.178] (HELO mail-wy0-f178.google.com) (74.125.82.178) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 13 Jul 2010 13:04:13 +0000 Received: by wyb38 with SMTP id 38so4964385wyb.37 for ; Tue, 13 Jul 2010 06:02:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:sender:from:content-type :subject:date:references:to:message-id:mime-version:x-mailer; bh=mcI2dGCuKJKZsFb/wlf3h8T2n9Md+jUvi/HQyaMctxM=; b=SCx4qLxcFSDAZeZh7jtjG+n/hTs9ZiLl68crfWTlPTbR8F72aow+RtphLVsb/o0/UN lpLCgvaWYwWoYRQ7T9V9/wfZqtEt/3bjKo/ORsUYNMcA4mBzWvusJaAASHM20YX+hrIO HyR2cQAwyd/cszFVClZfo4XnbfvwI2vYBpLnw= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=sender:from:content-type:subject:date:references:to:message-id :mime-version:x-mailer; b=SYrU35ihO/EnM0E4wkXsRP4uLp815EZf3vOn0evLbpmXmV+976f54nmRm5Gt3OWnQN yn0T1+etxuB05itbMezisQVkW2aoXJvH+SB3e+BUYnkvprfCzTV6Ze0Prfj2PFmaQdEH apSGW6xS4akbQ5IHVss2Iof1/ISkSoRamTpXA= Received: by 10.227.208.85 with SMTP id gb21mr2915740wbb.167.1279026172202; Tue, 13 Jul 2010 06:02:52 -0700 (PDT) Received: from [192.168.0.52] (lon92-10-78-226-4-211.fbx.proxad.net [78.226.4.211]) by mx.google.com with ESMTPS id i25sm39346334wbi.22.2010.07.13.06.02.51 (version=TLSv1/SSLv3 cipher=RC4-MD5); Tue, 13 Jul 2010 06:02:51 -0700 (PDT) Sender: Pierre-Arnaud Marcelot From: Pierre-Arnaud Marcelot Content-Type: multipart/alternative; boundary=Apple-Mail-1-71257669 Subject: Should we request an ASF-signed certificate from infra to sign Studio during a release? (was: Fwd: apache directory studio certificate) Date: Tue, 13 Jul 2010 15:02:48 +0200 References: To: Apache Directory Developers List Message-Id: <45DB8569-B9AC-439D-A095-0FF2E2388A43@marcelot.net> Mime-Version: 1.0 (Apple Message framework v1081) X-Mailer: Apple Mail (2.1081) X-Virus-Checked: Checked by ClamAV on apache.org --Apple-Mail-1-71257669 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii Hi dev, I'm forwarding a mail received on the users list about certificate usage = on Studio. Apache Directory Studio jars (including plugins and features) are all = signed using the keytool command during the build of a release. This certificate allows Eclipse to verify the validity of the software = during the installation with the update site. Until now, we were using a self-signed certificate which, as it is = self-signed, only lasts 6 months. As you can see on the mail below, this situation is causing some issue. Stefan suggested me on IM that for the next releases we could request an = ASF-signed certificate from infra. I think it's a good idea. WDOT ? Does anyone know if infra can provide us such a certificate ? Thanks, Pierre-Arnaud Begin forwarded message: > From: Pierre-Arnaud Marcelot > Date: 13 juillet 2010 14:52:15 HAEC > To: users@directory.apache.org > Subject: Re: apache directory studio certificate >=20 > Hi Nicolas, >=20 > I'm neither a certificate expert, but I did the signing of the jars = and the certificate is on my machine. >=20 > I exported the public key at this location for you: > http://people.apache.org/~pamarcelot/studio.cer >=20 > I hope it worked... >=20 > Regards, > Pierre-Arnaud >=20 > On 13 juil. 2010, at 14:22, Nicolas Dordet wrote: >=20 >> Hi all, >>=20 >> I'm trying to install ldap browser eclipse plugin by command line >> ($INSTDIR\IDE\eclipse\eclipsec -application = org.eclipse.equinox.p2.director >> -repository $URLUpdateSite -installIU >> = org.apache.directory.studio.ldapbrowser.feature.feature.group/1.5.3.v20100= 330") >> but I get an error message : "certificat rejected" >> Note that the certificate is out of date but the update site = installation >> works well. >>=20 >> (I'm not a certificate expert). >> I try to import the STUDIO.DSA (I found it in the feature jar) in my >> keystore with keytool but I could'nt. >>=20 >> So, where can I find the public key and how could I import it to my >> keystore? >>=20 >> I also try to build the plugin (thinking I could put away the = certificate >> request but I didn't find it) and I've got the same error. >>=20 >>=20 >> Any help needed >>=20 >> Thanks >=20 --Apple-Mail-1-71257669 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii Hi = dev,

I'm forwarding a mail received on the users list = about certificate usage on Studio.

Apache = Directory Studio jars (including plugins and features) are all signed = using the keytool command during the build of a release.
This = certificate allows Eclipse to verify the validity of the software during = the installation with the update site.

Until = now, we were using a self-signed certificate which, as it is = self-signed, only lasts 6 months.
As you can see on the mail = below, this situation is causing some = issue.

Stefan suggested me on IM that for the = next releases we could request an ASF-signed certificate from = infra.
I think it's a good idea.
WDOT = ?

Does anyone know if infra can provide us such = a certificate = ?

Thanks,
Pierre-Arnaud

<= div>
Begin forwarded message:

From: Pierre-Arnaud = Marcelot <pa@marcelot.net>
Date: 13 juillet 2010 = 14:52:15 HAEC
Subject: Re: apache directory studio = certificate

Hi Nicolas,

I'm neither = a certificate expert, but I did the signing of the jars and the = certificate is on my machine.

I exported the public key at this = location for you:
http://people.apa= che.org/~pamarcelot/studio.cer

I hope it = worked...

Regards,
Pierre-Arnaud

On 13 juil. 2010, at = 14:22, Nicolas Dordet wrote:

Hi = all,

I'm trying to = install ldap browser eclipse plugin by command = line
($INSTDIR\IDE\eclipse\eclipsec -application = org.eclipse.equinox.p2.director
-repository $URLUpdateSite = -installIU
org.apache.directory.studio.ldapbrowser.feature.feature.grou= p/1.5.3.v20100330")
but I get = an error message : "certificat rejected"
Note that the certificate is out of date but the update = site installation
works = well.

(I'm not a = certificate expert).
I try to = import the STUDIO.DSA (I found it in the feature jar) in = my
keystore with keytool but I = could'nt.

So, where can I = find the public key and how could I import it to = my
keystore?

I also try to = build the plugin (thinking I could put away the = certificate
request but I = didn't find it) and I've got the same error.


Any help = needed

Thanks


= --Apple-Mail-1-71257669--