www-infrastructure-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From J├╝rgen Schmidt <jogischm...@googlemail.com>
Subject Official code signing certificate
Date Mon, 11 Jun 2012 14:03:00 GMT

I would like to ask what step are necessary to get an official Apache
code signing certificate.

We would need such a certificate to sign our Apache OpenOffie binary
releases and make them trusted in the windows world with Apache as

Note: 87% of our >3000000 downloads of AOO 3.4 are from Windows

Especially with the upcoming Windows 8 app store this becomes even more

We had signed our releases ion the past and we have some tooling in
place in our build process. The details course have to be figured out
but that should be hopefully a minor problem.

The questions are
1. how can we get an official valid Apache code signing certificate
1.1 which steps are necessary because it is not for free

2. how can we use it in our build process or better how can we make it
useable for a limited group of users (I would say at least 3 PMC members
to have enough fall backs) to sign the final releases.

Any feedback or hint how to address this is correctly are welcome.



View raw message