[
https://issues.jboss.org/browse/JBIDE-13407?page=com.atlassian.jira.plugi...
]
Nick Boldt commented on JBIDE-13407:
------------------------------------
Nope. Infrastructure challenges prevent this from happening in the process I'd wanted
to implement (similar to the process at
Eclipse.org: pass a CI build's output to a
signing server, wait until signed, then retrieve the signed bits & collect them into
the downstream aggregates/products).
We could do potentially do a one-off manual build and sign that (rather than the above CI
process) but that's manual-heavy and not very reproduceable. So I'd prefer to
avoid a manual step.
If this is something that you feel is important / urgent to be solved before the end of
the Oxygen stream, let me know and I can attempt to escalate to ops to see what we could
do to implement this.
Jar signing for JBT plugins/features
------------------------------------
Key: JBIDE-13407
URL:
https://issues.jboss.org/browse/JBIDE-13407
Project: Tools (JBoss Tools)
Issue Type: Feature Request
Components: build, updatesite
Affects Versions: 3.3.2.Final, 4.0.0.Final, 4.1.0.Alpha1
Reporter: Nick Boldt
Assignee: Nick Boldt
Priority: Optional
Fix For: LATER
Attachments: JBDS6-STS272-install-from-central-Unsigned-Content-Warning.png,
dialog_do-you-trust-these-certs.png, jbds-signed-plugins.png,
no-more-jboss-unsigned-content-but-what-about-org.sonatype.png
Investigate jar signing processes/options and locations of certs we can use for signing
of JBIDE / JBTIS community jars for repackaging into JBDS product.
Goal is to avoid seeing warning about installing unsigned content from Eclipse
Marketplace, p2 installer, or JBoss Central.
--
This message was sent by Atlassian JIRA
(v7.5.0#75005)