http://bugs.winehq.org/show_bug.cgi?id=54836 --- Comment #12 from Hans Leidekker <hans@meelstraat.net> --- (In reply to Austin English from comment #11)
(In reply to Hans Leidekker from comment #9)
Wine already treats builtin dll signatures as trustworthy if the certificate chain leads to a trusted root CA but these signing certificates cost money and it seems unlikely that Linux distributions would take on this task.
Is this documented?
You mean signing builtin dlls? You could use standard Windows tools to do it. On Linux there's osslsigncode (ignoring timestamping): for dll in $(ls *.{dll,sys,drv,acm}); do echo "Signing $dll" osslsigncode sign -pkcs12 signcert.p12 -in $dll -out $dll.signed if [ $? -ne 0 ]; then exit 1 fi mv $dll.signed $dll chmod +x $dll # osslsigncode doesn't preserve executable bit done
An alternative might be to include a script that generates a self-signed signing certificate when Wine is installed, signs Wine dlls with it and adds the corresponding CA to the local trust database.
I think this is a great idea, and either this ticket should be repurposed for that, or a new one opened.
I think this is actually a packaging bug but I would keep this one or a new one open to collect duplicates. -- Do not reply to this email, post in Bugzilla using the above URL to reply. You are receiving this mail because: You are watching all bug changes.