Comments (8)
We have created an issue in Pivotal Tracker to manage this:
https://www.pivotaltracker.com/story/show/151457684
The labels on this github issue will be updated when the story is started.
from cli-plugin-repo.
@chipchilders Can you answer these questions?
from cli-plugin-repo.
(Certificates should only be used to sign binaries that the owner of the certificate is willing to vouch for... I wouldn't expect to see the CFF certs used for signing plugins unless CFF is providing the builds.)
from cli-plugin-repo.
@drnic you can't use the CFF certs for non-CFF projects
The process was pretty complex from the CLI team's side. All I helped with was the purchase (and required organizational verification process) for both an official Apple code signing cert and a Windows code signing cert. The Apple one comes from Apple (you need a developer account with them) and the Windows code signing cert came from a commercial certificate authority.
@dkoper - the CLI team should have information about how the certs are used to build and sign the CLI binary itself. LInking to that might be helpful for everyone.
from cli-plugin-repo.
from cli-plugin-repo.
This Quora article was somewhat helpful for us (though we haven't actually bought yet for cloud.gov to government obstacles).
from cli-plugin-repo.
I have added a bit more detail to https://github.com/cloudfoundry-incubator/cli-plugin-repo#sign-windows-binaries. In particular, more info of the type of code signing cert to help you google it.
For the Windows certs you need to select a commercial cert provider. I don't think we can/should do that selection or recommend a particular one. Also, a price comparison, even including a rough price range in every currency that the cf CLI is available feels a bit out of scope for our team to provide..
from cli-plugin-repo.
Closing. With the PR from @mogul merged I think all guidance is there.
from cli-plugin-repo.
Related Issues (20)
- feature request: allow CLIPR to be available to everyone HOT 5
- Best way to debug plugin HOT 2
- Windows binary signing instructions needed HOT 3
- Support SHA 256 checksums HOT 1
- Travis failure: Plugin 'Copy Env' has an invalid checksum for platform 'osx' HOT 4
- cf uninstall-plugin [name] runs the plugin before actually uninstalling HOT 3
- This is a test issue to test the new github integration HOT 2
- --password flag records password in shell history file HOT 4
- Remove cf recycle because of major bug HOT 3
- allow multiple versions of a plugin to coexist in the repo HOT 2
- Plugin Repository HOT 2
- Can author be an array? HOT 4
- Unable to install cfdev Plugin HOT 2
- Feature Request: support arm64 binaries for newer macs HOT 2
- Can't list community plugins - Invalid json data from 'CF-Community' HOT 1
- spring-cloud-services-cli-plugin 1.0.24 installation should mention 1.0.24 version (not 1.0.23) HOT 2
- plugins.cloudfoundry.org shouldn't be available via plain http HOT 4
- Binaries HOT 3
- feature request: add RSS/Atom feed of plugins HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from cli-plugin-repo.