From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.emacs.gnus.general/75734 Path: news.gmane.org!not-for-mail From: Ted Zlatanov Newsgroups: gmane.emacs.gnus.general Subject: Re: How do I configure a CA? Date: Thu, 20 Jan 2011 15:05:32 -0600 Organization: =?utf-8?B?0KLQtdC+0LTQvtGAINCX0LvQsNGC0LDQvdC+0LI=?= @ Cienfuegos Message-ID: <87wrlzl203.fsf@lifelogs.com> References: <8739pseujz.fsf@member.fsf.org> <87wrn4bcm6.fsf@member.fsf.org> NNTP-Posting-Host: lo.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: dough.gmane.org 1295557560 17571 80.91.229.12 (20 Jan 2011 21:06:00 GMT) X-Complaints-To: usenet@dough.gmane.org NNTP-Posting-Date: Thu, 20 Jan 2011 21:06:00 +0000 (UTC) To: ding@gnus.org Original-X-From: ding-owner+M24085@lists.math.uh.edu Thu Jan 20 22:05:56 2011 Return-path: Envelope-to: ding-account@gmane.org Original-Received: from util0.math.uh.edu ([129.7.128.18]) by lo.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1Pg1hZ-0001Om-K1 for ding-account@gmane.org; Thu, 20 Jan 2011 22:05:53 +0100 Original-Received: from localhost ([127.0.0.1] helo=lists.math.uh.edu) by util0.math.uh.edu with smtp (Exim 4.63) (envelope-from ) id 1Pg1hU-0005XK-Lg; Thu, 20 Jan 2011 15:05:48 -0600 Original-Received: from mx1.math.uh.edu ([129.7.128.32]) by util0.math.uh.edu with esmtps (TLSv1:AES256-SHA:256) (Exim 4.63) (envelope-from ) id 1Pg1hT-0005XC-Lc for ding@lists.math.uh.edu; Thu, 20 Jan 2011 15:05:47 -0600 Original-Received: from quimby.gnus.org ([80.91.231.51]) by mx1.math.uh.edu with esmtp (Exim 4.72) (envelope-from ) id 1Pg1hS-0007xP-RS for ding@lists.math.uh.edu; Thu, 20 Jan 2011 15:05:47 -0600 Original-Received: from lo.gmane.org ([80.91.229.12]) by quimby.gnus.org with esmtp (Exim 4.72) (envelope-from ) id 1Pg1hS-00011G-54 for ding@gnus.org; Thu, 20 Jan 2011 22:05:46 +0100 Original-Received: from list by lo.gmane.org with local (Exim 4.69) (envelope-from ) id 1Pg1hQ-0001J6-RX for ding@gnus.org; Thu, 20 Jan 2011 22:05:44 +0100 Original-Received: from 38.98.147.130 ([38.98.147.130]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 20 Jan 2011 22:05:44 +0100 Original-Received: from tzz by 38.98.147.130 with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Thu, 20 Jan 2011 22:05:44 +0100 X-Injected-Via-Gmane: http://gmane.org/ Original-Lines: 16 Original-X-Complaints-To: usenet@dough.gmane.org X-Gmane-NNTP-Posting-Host: 38.98.147.130 X-Face: bd.DQ~'29fIs`T_%O%C\g%6jW)yi[zuz6;d4V0`@y-~$#3P_Ng{@m+e4o<4P'#(_GJQ%TT= D}[Ep*b!\e,fBZ'j_+#"Ps?s2!4H2-Y"sx" User-Agent: Gnus/5.110011 (No Gnus v0.11) Emacs/24.0.50 (gnu/linux) Cancel-Lock: sha1:UTQCEImUbK45MpkiTKVS+9VNSPo= X-Spam-Score: -0.7 (/) List-ID: Precedence: bulk Xref: news.gmane.org gmane.emacs.gnus.general:75734 Archived-At: On Mon, 20 Dec 2010 18:03:29 +0100 Tassilo Horn wrote: TH> ok, if OpenSSL is too much a hassle and EPA is better anyways, I won't TH> try that out. :-) This brings up an issue related to the GnuTLS support in Emacs and Gnus: is there a difference between the CAs bundled with EPA/EPG (which eventually delegates to GPG, I think) and OpenSSL (which has its own list)? I ask because I eventually have to build a list of CAs for Emacs' GnuTLS support so it can verify certificates. I'd like that list to be consistent with EPA/EPG, but does that sacrifice some security or inconvenience users? Ted