GNU bug report logs -
#28170
Add gnutls/dane + use it where its needed (gnurl, libmicrohttpd, gnunet)
Previous Next
Reported by: ng0 <ng0 <at> infotropique.org>
Date: Mon, 21 Aug 2017 09:59:02 UTC
Severity: normal
Done: Christopher Baines <mail <at> cbaines.net>
Bug is archived. No further changes may be made.
Full log
View this message in rfc822 format
[Message part 1 (text/plain, inline)]
Your bug report
#28170: Add gnutls/dane + use it where its needed (gnurl, libmicrohttpd, gnunet)
which was filed against the guix-patches package, has been closed.
The explanation is attached below, along with your original report.
If you require more details, please reply to 28170 <at> debbugs.gnu.org.
--
28170: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=28170
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
[Message part 3 (text/plain, inline)]
On Sat, 30 Sep 2017 16:36:05 +0000
ng0 <ng0 <at> infotropique.org> wrote:
> Christopher Baines transcribed 3.6K bytes:
> > On Sat, 30 Sep 2017 15:01:52 +0000
> > ng0 <ng0 <at> infotropique.org> wrote:
> >
> > > ng0 transcribed 2.1K bytes:
> > > > Christopher Baines transcribed 1.7K bytes:
> > > > > On Sat, 30 Sep 2017 14:12:55 +0000
> > > > > ng0 <ng0 <at> infotropique.org> wrote:
> > > > >
> > > > > > The fix in this version is to only add the necessary input
> > > > > > to the inherited gnutls.
> > > > >
> > > > > Ok. One hopefully final thing. From the commit message [1],
> > > > > it's not clear to me if this is fixing an issue with the
> > > > > GNUnet package, by providing it with the right dependencies,
> > > > > or, adding additional functionality to the GNUnet package, by
> > > > > providing a more capable GnuTLS?
> > > > >
> > > > > 1: "GNUnet and its dependency chain needs GnuTLS with DANE
> > > > > support."
> > > > It provides the right GnuTLS to GNUnet, libmicrohttpd and gnURL.
> > > > Certain features of these applications will not work without it.
> > > > GnuTLS without Dane is not fatal error for these packages, but
> > > > Dane is recommended.
> > > > I have no idea how I should put this into the very strict
> > > > dictionary we have in commit messages… In more free-form it
> > > > would be no problem for me.
> > > > --
> > > > ng0
> > > > GnuPG: A88C8ADD129828D7EAC02E52E22F9BBFEE348588
> > > > GnuPG: https://krosos.org/dist/keys/
> > > > https://www.infotropique.org https://krosos.org
> > >
> > > Okay, I now see what you mean.
> > >
> > > To make it short: the correct dependency is provided in place
> > > of the current working-but-not-correct GnuTLS.
> > >
> > > Is that more clear?
> >
> > I think you've made it clear to me now.
> >
> > From what you're saying, I think its the 2nd thing I said. Making
> > this change will enable some functionality in the GNUnet package
> > (and possibly some of the other packages changed).
> >
> > I'm not sure using the word "correct" helps, unless you say what the
> > dependencies are correct/incorrect with respect to, for example, if
> > the GNUnet documentation says that it should be built with GnuTLS
> > with Dane support, then that would be a reason to talk about
> > correctness.
>
> Yes it does state this, in the documentation and all these
> applications list the dependency in README aswell.
> This is why I thought the original, first version, comment I made in
> gnutls/dane was enough. But I'll have to be more clear then.
> Well if gnURL doesn't state it in its README I have to add it, if it's
> not in there it's my mistake - it's correct nevertheless.
>
> > As for the commit format. As I understand the conventions, you can
> > put anything in between the first line, and the changelog at the
> > bottom. For example, one case where I ended up writing quite a bit
> > is here [1].
> >
> > It doesn't have to be very specific, but something about the intent
> > or intended effect of the change in each commit would be very
> > useful.
> >
> > 1:
> > http://git.savannah.gnu.org/cgit/guix.git/commit/?id=6230e155afd8c43c12ee3f03032aac34433db11a
>
> Okay, thanks. I will change the commit messages and
> reference our (GNUnet) README and documentation sections.
I've now merged the patches that were attached to this email :)
Thanks,
Chris
[Message part 4 (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
[Message part 6 (text/plain, inline)]
The dependency chain of GNUnet demands GnuTLS with DANE support.
You can use it without DANE, but there are certain parts which
will not work. DANE is recommended. (ports of FREEBSD uses
gnutls-dane for libmicrohttpd aswell for example).
The attached patches:
- Add 'gnutls/dane'
- Use it in
- libmicrohttpd
- gnurl
- gnunet
--
ng0
GnuPG: A88C8ADD129828D7EAC02E52E22F9BBFEE348588
GnuPG: https://n0is.noblogs.org/my-keys
https://www.infotropique.org https://krosos.org
[0001-gnu-gnutls-Add-gnutls-dane.patch (text/plain, attachment)]
[0002-gnu-gnurl-Use-gnutls-dane-as-input.patch (text/plain, attachment)]
[0003-gnu-libmicrohttpd-Use-gnutls-dane-as-input.patch (text/plain, attachment)]
[0004-gnu-gnunet-Use-gnutls-dane-as-input.patch (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]
This bug report was last modified 7 years and 231 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.