Skip to Content.
Sympa Menu

cacert-devel - Re: motion to authorise editors and PolO to exchange policy documents

Subject: CAcert Code Development list.

List archive

Re: motion to authorise editors and PolO to exchange policy documents


Chronological Thread 
  • From: Ian G <iang AT cacert.org>
  • To: cacert-policy AT lists.cacert.org
  • Cc: cacert-devel AT lists.cacert.org
  • Subject: Re: motion to authorise editors and PolO to exchange policy documents
  • Date: Wed, 04 Feb 2015 10:43:12 +0000

On 3/02/2015 22:30 pm, Benny Baumann wrote:
Thus: What you do while WIP is your business, but the versions effective
to our members should require established version control.


On the other hand... it does occur that there is one other risk. The crit system has to display the content of the policy to the users in the event of a new registration, or otherwise make it available. It has to get the "right" one and it has to make sure that it has no nasty stuff injected into it. In effect the high-sec site is displaying content from a medium-sec site, and therefore disturbing the security perimeter.

We (policy group and members and arbitration) will pick up the first risk. However the second risk probably means that crit system has to scrub the file every time it brings it in. Or cache it. Or scrub & hash it. Or...

Hmm, maybe this is overthinking it, maybe crit-system can simply display a link.

Maybe Policy is not the right group for this, CC to devel.

iang




Archive powered by MHonArc 2.6.18.

Top of Page