[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-26 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13423187#comment-13423187 ] Karl Pauls commented on FELIX-3610: --- I commited a patch to trunk in r1366063. Can you

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-26 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13423242#comment-13423242 ] Guillaume Nodet commented on FELIX-3610: It seems to work from my first tests,

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422417#comment-13422417 ] Guillaume Nodet commented on FELIX-3610: Note that the benefit of signing is that

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422508#comment-13422508 ] Guillaume Nodet commented on FELIX-3610: I initially tried using a JarInputStream

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422534#comment-13422534 ] Karl Pauls commented on FELIX-3610: --- I guess I'm not sure what you are saying.

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422547#comment-13422547 ] Guillaume Nodet commented on FELIX-3610: That's exactly the reason, to make sure

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422551#comment-13422551 ] Guillaume Nodet commented on FELIX-3610: One question though, did the check

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Richard S. Hall (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422554#comment-13422554 ] Richard S. Hall commented on FELIX-3610: If you assume that they can modify the

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422559#comment-13422559 ] Guillaume Nodet commented on FELIX-3610: Here's the problem I have. #1 I install

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422569#comment-13422569 ] Karl Pauls commented on FELIX-3610: --- How are you verifying the signatures? I assume you

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422577#comment-13422577 ] Guillaume Nodet commented on FELIX-3610: Not sure, I'm not designing this myself,

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422581#comment-13422581 ] Guillaume Nodet commented on FELIX-3610: Also, if the signatures are checked when

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Richard S. Hall (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422588#comment-13422588 ] Richard S. Hall commented on FELIX-3610: I think the way it is supposed to work is

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Guillaume Nodet (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422598#comment-13422598 ] Guillaume Nodet commented on FELIX-3610: Bundle permissions are not really the

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422603#comment-13422603 ] Karl Pauls commented on FELIX-3610: --- Regarding the theory, I can see that there are

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422608#comment-13422608 ] Karl Pauls commented on FELIX-3610: --- The security provider it not installed too late.

[jira] [Commented] (FELIX-3610) Support runtime verification for signed bundles

2012-07-25 Thread Karl Pauls (JIRA)
[ https://issues.apache.org/jira/browse/FELIX-3610?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13422662#comment-13422662 ] Karl Pauls commented on FELIX-3610: --- Ok, after talking about this via skype some more I