← Back to team overview

coapp-developers team mailing list archive

Re: Codesigning for the masses.

 

So now that I've followed this thread and finally found a chance to
get reply here are my thoughts:

What is required for someone to sign CoApp CLA? I don't remember
offhand, it's been a while.

Certum is probably filled with very nice people but their usability,
especially for non-Polish speakers is just atrocious. I applied for a
cert from them last year. The process went as follows:
 1. Stumble upon the proper form on their website, which seems to
switch between Polish and English for no apparently reason, for
applying for an open source cert.
 2.Fill out the form according to their instructions which seemed to
say I needed to use the word Open Source Developer in the name or the
organization (I can't remember which).
 3. When you're using Firefox, start over. It doesn't work in Firefox.
 4. After filling out the form, receive an email asking for a copy of
your id sent to them via email. No don't encrypt it, it's only your
personal government identification.
 5. Get an email, 2 days later telling you that you didn't put Open
Source Developer in the correct field (again it's name or
organization).,
 6. Fill out the form again.
 7. Get an email asking for your id again. Email them and politely
explain to them you already did this.
 8. When they confirm you via email, follow the link. Make sure you
use the same browser and computer you use before otherwise this whole
process will fail.
 9. The link goes to a page in Polish. Run it through Google Translate
to see what to do. After all, precision isn't important, this only
involves identifying you to the world.
10. Guess at the proper step from the mangled Google Translate result.
If you're lucky, you'll have your cert.
11. After a year, you'll get an email completely in Polish. Google
Translate seems to indicate that you need to renew your cert.
12. Click a link in the email which goes to the site for renewing a
certificate you paid for and asks for your credit card information,
not one for open source developers.
13. Cry and give up.

Let me make this very clear: under no circumstances would I ever
suggest someone use them. I don't know if they simply don't care that
their process is confusing, especially to non-Polish speakers, or if
they have no idea but I'm not willing to deal with them. Recommending
them to anyone would make us look bad and scare off good people who
aren't willing to put up with this.

I think a WOT plan is where we should go long term like Garrett
mentioned. We all know the CAs are basically a scam anyways so the
quicker we can make them completely irrelevant for open source, the
better off we all are.

Eric


On Wed, Jan 4, 2012 at 5:22 PM, Jernej Simončič
<jernej+s-launchpad@xxxxxxxxxxxxxxxxxx> wrote:
> On Thursday, January 5, 2012, 0:08:56, Mateusz Loskot wrote:
>
>> CERTUM is a company established in Poland.
>
> Well aware of that.
>
>> They have virtual branch at http://www.certum.eu/ for non-Polish users.
>
> The problem is, that even though they appear to be targeting
> international users, too, you often get redirected to the polish site.
>
> --
> < Jernej Simončič ><><><><>< http://eternallybored.org/ >
>
> Spend sufficient time confirming the need and the need will disappear.
>       -- Ed's Fifth Rule of Procrastination
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~coapp-developers
> Post to     : coapp-developers@xxxxxxxxxxxxxxxxxxx
> Unsubscribe : https://launchpad.net/~coapp-developers
> More help   : https://help.launchpad.net/ListHelp


Follow ups

References