| Summary: | Need better support for signing of features and plug-ins | ||
|---|---|---|---|
| Product: | [Eclipse Project] Platform | Reporter: | Adrian Cho <adrian_cho> |
| Component: | Runtime | Assignee: | platform-runtime-inbox <platform-runtime-inbox> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | enhancement | ||
| Priority: | P3 | CC: | celek, dreich, jeffmcaffer, john.arthorne, Kevin_Haaland, n.a.edgar, pascal |
| Version: | 3.1 | ||
| Target Milestone: | 3.3 | ||
| Hardware: | All | ||
| OS: | All | ||
| Whiteboard: | |||
|
Description
Adrian Cho
Has the UI team ever been notified of the item b)? Or do expect product providers to write their own? CC'ing Nick. This is news to me. I've filed bug 94461 for the About dialog, and tagged it for 3.2. If this is high priority for 3.1, please shout. The 3.1 signing effort is more about being *able to* verify the origins of plugins (and thus the validity of an install) than it is about actually checking. We will not be able to do the work for b) in 3.1. What would be interesting for "someone" to write is a tool that takes a list of pluigns and a set of certificates and verifies that the given plugins are in fact signed by the appropriate people. The initial impetus for this bugzilla report is that when adding features to the IDE, an ugly popup comes up that the feature is not signed. We have the check in there, but we don't have a certificate to sign against, so unless one gets a certificate, puts it in, then signs the feature against it, that popup will show every time something is added to the IDE. We should have a cert for IES that we can sign against, and anything we add will be signed and be happy. OR, we should turn off the check, or make it a perference to "check digital certificates when adding new features" so people can turn it off. This is not a major functional deficiency, but it really looks ugly. Jeff can you elaborate ? UM checks the cert used to sign a JAR is in one of teh valid keystore of Eclipse Also, even if the JAR is signed, UM will still prompt the user :( This is the way IE, Firefox and other seem to work. Not sure if we have to prompt for legal resons or not. Some amount of support for this is going into 3.2 but the full signing of the Eclipse supplied plugins is being deferred to 3.3 3.3 is signed |