Debian Bug report logs -
#597537
euca2ools: Please include the public EC2 certificate
Reported by: Miguel Landaeta <miguel@miguel.cc>
Date: Mon, 20 Sep 2010 16:24:01 UTC
Severity: wishlist
Tags: help
Merged with 573857
Found in version ca-certificates/20090814
Done: "Thijs Kinkhorst" <thijs@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, miguel@miguel.cc, Debian Eucalyptus Maintainers <pkg-eucalyptus-maintainers@lists.alioth.debian.org>:
Bug#597537; Package euca2ools.
(Mon, 20 Sep 2010 16:24:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Miguel Landaeta <miguel@miguel.cc>:
New Bug report received and forwarded. Copy sent to miguel@miguel.cc, Debian Eucalyptus Maintainers <pkg-eucalyptus-maintainers@lists.alioth.debian.org>.
(Mon, 20 Sep 2010 16:24:04 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: euca2ools
Version: 1.2-1
Severity: wishlist
Hi,
Is there any possibility to include the public EC2
certificate in this package?
I ask because I had problems bundling EC2 images until I
figured out that I need that certificate and I had to
install the non-free package ec2-ami-tools from Ubuntu which
includes this file.
I don't know if is possible to redistribute this file in
Debian, but this would be really useful if possible.
BTW, this issue was also opened in Ubuntu some time ago,
please check https://bugs.launchpad.net/ubuntu/+source/euca2ools/+bug/479836
Thanks,
-- System Information:
Debian Release: squeeze/sid
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) (ignored: LC_ALL set to en_US.UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages euca2ools depends on:
ii python 2.6.6-1 interactive high-level object-orie
ii python-boto 1.9b-4 Python interface to Amazon's Web S
ii python-central 0.6.16+nmu1 register and build utility for Pyt
ii python-m2crypto 0.20.1-1+b1 a crypto and SSL toolkit for Pytho
euca2ools recommends no packages.
euca2ools suggests no packages.
-- no debconf information
--
Miguel Landaeta, miguel at miguel.cc
secure email with PGP 0x7D8967E9 available at http://keyserver.pgp.com/
"Faith means not wanting to know what is true." -- Nietzsche
Bug No longer marked as found in versions euca2ools/1.2-1.
Request was from Charles Plessy <plessy@debian.org>
to control@bugs.debian.org.
(Tue, 21 Sep 2010 00:39:06 GMT) (full text, mbox, link).
Merged 573857 597537.
Request was from Charles Plessy <plessy@debian.org>
to control@bugs.debian.org.
(Tue, 21 Sep 2010 00:39:07 GMT) (full text, mbox, link).
Added indication that 597537 affects euca2ools
Request was from Charles Plessy <plessy@debian.org>
to control@bugs.debian.org.
(Tue, 21 Sep 2010 00:39:08 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Tue, 23 Aug 2011 03:51:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Charles Plessy <plessy@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Tue, 23 Aug 2011 03:51:03 GMT) (full text, mbox, link).
Message #18 received at 597537@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
severity 597537 normal
thanks
Dear all,
as per /usr/share/doc/ca-certificates/README.Debian, I am looking for
additional signed recommendations for the addition of the Amazon Elastic
Computer Cloud (EC2) public certificate to the ca-certificates packages.
In Ubuntu it is distributed in the euca2ools packages, that I co-maintain in
Debian, but for the following reasons I think that ca-certificates would be a
better place.
- The original upstream sources of euca2ools do not contain the certificate.
- The Upstream of euca2ools, Eucalyptus, and the provider of the EC2, Amazon,
are not the same company.
- The use of the certificate is not limited to euca2ools.
I attached a copy of the certificate. It is used to bundle machine images
for the EC2. I have not found a web page dedicated to its description.
SHA1 Fingerprint=D3:27:BA:A0:F8:D3:EE:9C:BB:3C:FB:FE:3B:52:65:A8:40:53:5D:0D
It was downloaded from http://s3.amazonaws.com/ec2-downloads/ec2-ami-tools.zip
Although the files in this archive are distributed under the non-free Amazon
Software License (http://aws.amazon.com/asl/), I think that public certificate
is not subject to a licence, since it is not the product of an intellectual
work.
Have a nice day,
--
Charles Plessy
Tsurumi, Kanagawa, Japan
[signature.asc (application/pgp-signature, inline)]
Severity set to 'normal' from 'wishlist'
Request was from Charles Plessy <plessy@debian.org>
to control@bugs.debian.org.
(Tue, 23 Aug 2011 03:51:05 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Tue, 23 Aug 2011 04:00:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Russ Allbery <rra@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Tue, 23 Aug 2011 04:00:03 GMT) (full text, mbox, link).
Message #25 received at 597537@bugs.debian.org (full text, mbox, reply):
Charles Plessy <plessy@debian.org> writes:
> as per /usr/share/doc/ca-certificates/README.Debian, I am looking for
> additional signed recommendations for the addition of the Amazon Elastic
> Computer Cloud (EC2) public certificate to the ca-certificates packages.
As someone not particularly familiar with the details of how certs work
inside EC2, my main question would be: what's the signing policy used by
the holder of the private key for this certificate?
--
Russ Allbery (rra@debian.org) <http://www.eyrie.org/~eagle/>
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Tue, 23 Aug 2011 17:27:06 GMT) (full text, mbox, link).
Acknowledgement sent
to Michael Shuler <michael@pbandjelly.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Tue, 23 Aug 2011 17:27:06 GMT) (full text, mbox, link).
Message #30 received at 597537@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
On 08/22/2011 10:56 PM, Russ Allbery wrote:
> Charles Plessy <plessy@debian.org> writes:
>
>> as per /usr/share/doc/ca-certificates/README.Debian, I am looking for
>> additional signed recommendations for the addition of the Amazon Elastic
>> Computer Cloud (EC2) public certificate to the ca-certificates packages.
>
> As someone not particularly familiar with the details of how certs work
> inside EC2, my main question would be: what's the signing policy used by
> the holder of the private key for this certificate?
This is also my question - is this a CA that will be verifying and
signing other certs? (I'll try to dig on the same info, as well)
For the record, I intend to adopt ca-certificates relatively soon, as I
have not heard back from the previous ITA poster in a few weeks. The
package needs some TLC and I have some updates already queued up, but
not pushed to my git repo, yet :-)
--
Kind regards,
Michael
[signature.asc (application/pgp-signature, attachment)]
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Tue, 23 Aug 2011 20:39:06 GMT) (full text, mbox, link).
Acknowledgement sent
to Miguel Landaeta <miguel@miguel.cc>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Tue, 23 Aug 2011 20:39:06 GMT) (full text, mbox, link).
Message #35 received at 597537@bugs.debian.org (full text, mbox, reply):
On Tue, Aug 23, 2011 at 12:53 PM, Michael Shuler <michael@pbandjelly.org> wrote:
> This is also my question - is this a CA that will be verifying and
> signing other certs? (I'll try to dig on the same info, as well)
AFAIK, this certificate is only used to encrypt your AMIs and transfer them
securely to Amazon. In this way only you and Amazon know about the content
of your AMI, Amazon needs this in order to launch your AMIs in their cloud.
--
Miguel Landaeta, miguel at miguel.cc
secure email with PGP 0x7D8967E9 available at http://keyserver.pgp.com/
"Faith means not wanting to know what is true." -- Nietzsche
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Wed, 24 Aug 2011 11:45:28 GMT) (full text, mbox, link).
Acknowledgement sent
to Stefano Rivera <stefanor@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Wed, 24 Aug 2011 11:45:29 GMT) (full text, mbox, link).
Message #40 received at 597537@bugs.debian.org (full text, mbox, reply):
Hi Miguel (2011.08.23_22:34:47_+0200)
> AFAIK, this certificate is only used to encrypt your AMIs and transfer them
> securely to Amazon. In this way only you and Amazon know about the content
> of your AMI, Amazon needs this in order to launch your AMIs in their cloud.
That's what I've heard (although non-definitively) from someone who used
to maintain ec2-ami-tools for Amazon.
And as Russ asked:
> Hm, then it's not actually a CA, is it?
Correct. It's just some public key material for encryption.
SR
--
Stefano Rivera
http://tumbleweed.org.za/
H: +27 21 465 6908 C: +27 72 419 8559 UCT: x3127
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#597537; Package ca-certificates.
(Thu, 25 Aug 2011 02:09:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Charles Plessy <plessy@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>.
(Thu, 25 Aug 2011 02:09:03 GMT) (full text, mbox, link).
Message #45 received at 597537@bugs.debian.org (full text, mbox, reply):
Le Wed, Aug 24, 2011 at 03:06:11PM +0000, Philipp Kern a écrit :
> On 2011-08-23, Russ Allbery <rra@debian.org> wrote:
> > It seems strange to include a non-CA certificate in ca-certificates; we
> > may need a different sort of infrastructure to handle things like this.
> > (And I think it would be a bit questionable to trust any certificate
> > signed by that certificate in a web browser, say, which is what would
> > happen if it were just included in ca-certificates.)
>
> Yep, it's the wrong place. Furthermore, if we are not allowed to distribute
> it, we shouldn't. And if other open-source projects don't ship it, that's
> fairly good clue that we shouldn't, neither.
Thanks everybody who explained better the usage of this certificate. As
others, I now think that a good place for it would be in a future cloud support
package, for instance cloud-utils (http://bugs.debian.org/622946).
There is no indication that the certificate is not redistributable, and there
is at least one other project that redistributes it (Ubuntu, in the euca2ools
package).
Have a nice day,
--
Charles Plessy
Tsurumi, Kanagawa, Japan
Information forwarded
to debian-bugs-dist@lists.debian.org:
Bug#597537; Package ca-certificates.
(Sat, 29 Oct 2011 00:36:25 GMT) (full text, mbox, link).
Acknowledgement sent
to Michael Shuler <michael@pbandjelly.org>:
Extra info received and forwarded to list.
(Sat, 29 Oct 2011 00:36:25 GMT) (full text, mbox, link).
Message #50 received at 597537@bugs.debian.org (full text, mbox, reply):
tag 573857 + help
tag 597537 + help
thanks
As Charles mentioned in #597537 [0], the EC2 AMI certificate is
distributed in the euca2ools package in Ubuntu - should it live in
euca2ools in Debian? Or, perhaps in the future cloud-utils package [1],
as Charles mentions later in the same bug report?
I am working on cleaning up the ca-certificates bug list and since AWS
EC2 is not a signing Certificate Authority, I don't think it is
appropriate for ca-certificates. I would like to reassign the merged
bugs #573857 and #597537 to a proper package that would like to include
the EC2 certificate. Thoughts?
[0] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=597537#18
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622946
--
Kind regards,
Michael Shuler
Added tag(s) help.
Request was from Michael Shuler <michael@pbandjelly.org>
to control@bugs.debian.org.
(Sat, 29 Oct 2011 00:36:29 GMT) (full text, mbox, link).
Severity set to 'wishlist' from 'normal'
Request was from Michael Shuler <michael@pbandjelly.org>
to control@bugs.debian.org.
(Sat, 29 Oct 2011 00:36:32 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Michael Shuler <michael@pbandjelly.org>:
Bug#597537; Package ca-certificates.
(Tue, 11 Jun 2013 10:57:03 GMT) (full text, mbox, link).
Acknowledgement sent
to "Thijs Kinkhorst" <thijs@debian.org>:
Extra info received and forwarded to list. Copy sent to Michael Shuler <michael@pbandjelly.org>.
(Tue, 11 Jun 2013 10:57:03 GMT) (full text, mbox, link).
Message #59 received at 597537@bugs.debian.org (full text, mbox, reply):
Hi Charles,
> As Charles mentioned in #597537 [0], the EC2 AMI certificate is
> distributed in the euca2ools package in Ubuntu - should it live in
> euca2ools in Debian? Or, perhaps in the future cloud-utils package [1],
> as Charles mentions later in the same bug report?
>
> I am working on cleaning up the ca-certificates bug list and since AWS
> EC2 is not a signing Certificate Authority, I don't think it is
> appropriate for ca-certificates. I would like to reassign the merged
> bugs #573857 and #597537 to a proper package that would like to include
> the EC2 certificate. Thoughts?
Can you advise on this?
thanks,
Thijs
Information forwarded
to debian-bugs-dist@lists.debian.org, Michael Shuler <michael@pbandjelly.org>:
Bug#597537; Package ca-certificates.
(Tue, 11 Jun 2013 23:33:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Charles Plessy <plessy@debian.org>:
Extra info received and forwarded to list. Copy sent to Michael Shuler <michael@pbandjelly.org>.
(Tue, 11 Jun 2013 23:33:04 GMT) (full text, mbox, link).
Message #64 received at 597537@bugs.debian.org (full text, mbox, reply):
Le Tue, Jun 11, 2013 at 12:55:52PM +0200, Thijs Kinkhorst a écrit :
>
> > As Charles mentioned in #597537 [0], the EC2 AMI certificate is
> > distributed in the euca2ools package in Ubuntu - should it live in
> > euca2ools in Debian? Or, perhaps in the future cloud-utils package [1],
> > as Charles mentions later in the same bug report?
> >
> > I am working on cleaning up the ca-certificates bug list and since AWS
> > EC2 is not a signing Certificate Authority, I don't think it is
> > appropriate for ca-certificates. I would like to reassign the merged
> > bugs #573857 and #597537 to a proper package that would like to include
> > the EC2 certificate. Thoughts?
>
> Can you advise on this?
Hi Thijs and everybody,
how about proposing a new binary package in the ca-certificates source package ?
I see http://wiki.debian.org/X.509 and this new binary package could follow
a policy along these lines.
Cheers,
--
Charles Plessy
Tsurumi, Kanagawa, Japan
Information forwarded
to debian-bugs-dist@lists.debian.org, Michael Shuler <michael@pbandjelly.org>:
Bug#597537; Package ca-certificates.
(Wed, 12 Jun 2013 06:39:04 GMT) (full text, mbox, link).
Acknowledgement sent
to "Thijs Kinkhorst" <thijs@debian.org>:
Extra info received and forwarded to list. Copy sent to Michael Shuler <michael@pbandjelly.org>.
(Wed, 12 Jun 2013 06:39:04 GMT) (full text, mbox, link).
Message #69 received at 597537@bugs.debian.org (full text, mbox, reply):
On Wed, June 12, 2013 01:28, Charles Plessy wrote:
> Le Tue, Jun 11, 2013 at 12:55:52PM +0200, Thijs Kinkhorst a écrit :
>>
>> > As Charles mentioned in #597537 [0], the EC2 AMI certificate is
>> > distributed in the euca2ools package in Ubuntu - should it live in
>> > euca2ools in Debian? Or, perhaps in the future cloud-utils package
>> [1],
>> > as Charles mentions later in the same bug report?
>> >
>> > I am working on cleaning up the ca-certificates bug list and since AWS
>> > EC2 is not a signing Certificate Authority, I don't think it is
>> > appropriate for ca-certificates. I would like to reassign the merged
>> > bugs #573857 and #597537 to a proper package that would like to
>> include
>> > the EC2 certificate. Thoughts?
>>
>> Can you advise on this?
>
> Hi Thijs and everybody,
>
> how about proposing a new binary package in the ca-certificates source
> package ?
> I see http://wiki.debian.org/X.509 and this new binary package could
> follow
> a policy along these lines.
I'm not sure what the source of that wiki page is nor do I think it has
current consensus or implementation. At least it doesn't stem from the
ca-certificates maintainers.
As with your proposal for a new binary package: I'm not sure we have
enough content currently to justify such a thing. We currently have the
suggestion to add the EC2 certificate only.
What do you think about adding the certificate in a package more
specifically geared to this specialist use case? After all, the
certificate is not generally usable, only with this specific service. The
euca2ools package was suggested as a good place, where Ubuntu seems to
keep it aswell, or something like cloud-init?
Cheers,
Thijs
Information forwarded
to debian-bugs-dist@lists.debian.org, Michael Shuler <michael@pbandjelly.org>:
Bug#597537; Package ca-certificates.
(Sat, 15 Jun 2013 06:27:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Charles Plessy <plessy@debian.org>:
Extra info received and forwarded to list. Copy sent to Michael Shuler <michael@pbandjelly.org>.
(Sat, 15 Jun 2013 06:27:04 GMT) (full text, mbox, link).
Message #74 received at 597537@bugs.debian.org (full text, mbox, reply):
Le Wed, Jun 12, 2013 at 08:36:42AM +0200, Thijs Kinkhorst a écrit :
>
> What do you think about adding the certificate in a package more
> specifically geared to this specialist use case? After all, the
> certificate is not generally usable, only with this specific service. The
> euca2ools package was suggested as a good place, where Ubuntu seems to
> keep it aswell, or something like cloud-init?
Hi Thijs,
I still do not like the idea of adding the certificate to euca2ools,
but I will do it. If some other developers create a package to contain
similar certificates, I will be happy to transfer it later.
(Note that the certificate is useful with other implementations of the
Amazon API.)
Have a nice week-end,
--
Charles
Reply sent
to "Thijs Kinkhorst" <thijs@debian.org>:
You have taken responsibility.
(Sat, 15 Jun 2013 08:15:08 GMT) (full text, mbox, link).
Notification sent
to Miguel Landaeta <miguel@miguel.cc>:
Bug acknowledged by developer.
(Sat, 15 Jun 2013 08:15:08 GMT) (full text, mbox, link).
Message #79 received at 597537-done@bugs.debian.org (full text, mbox, reply):
Hi Charles,
On Sat, June 15, 2013 08:24, Charles Plessy wrote:
> Le Wed, Jun 12, 2013 at 08:36:42AM +0200, Thijs Kinkhorst a écrit :
>>
>> What do you think about adding the certificate in a package more
>> specifically geared to this specialist use case? After all, the
>> certificate is not generally usable, only with this specific service.
>> The
>> euca2ools package was suggested as a good place, where Ubuntu seems to
>> keep it aswell, or something like cloud-init?
>
> Hi Thijs,
>
> I still do not like the idea of adding the certificate to euca2ools,
> but I will do it. If some other developers create a package to contain
> similar certificates, I will be happy to transfer it later.
>
> (Note that the certificate is useful with other implementations of the
> Amazon API.)
>
> Have a nice week-end,
Thanks. It may not be perfect but I believe it's the right way to go at
this point. Of course we can change things anytime later when it makes
sense.
Cheers,
Thijs
Reply sent
to "Thijs Kinkhorst" <thijs@debian.org>:
You have taken responsibility.
(Sat, 15 Jun 2013 08:15:09 GMT) (full text, mbox, link).
Notification sent
to Charles Plessy <plessy@debian.org>:
Bug acknowledged by developer.
(Sat, 15 Jun 2013 08:15:09 GMT) (full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Sun, 14 Jul 2013 07:31:41 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sat Jul 1 14:02:54 2023;
Machine Name:
bembo
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.