6f3b6a2fea
GnuTLS has a single hard-coded location for the system trust store, currently set to the path used by NixOS, Debian, Arch, Gentoo, etc. Since not all distributions use the same path, notably Fedora and RHEL, the certificate validation will break on some non-NixOS system. This can be solved by enabling the p11-kit integration, so that by default p11-kit (properly configured for all major distos) will provide GnuTLS with the CA roots though the PKCS #11 API. |
||
---|---|---|
.. | ||
default.nix | ||
dummy.crt | ||
nix-ssl-cert-file.patch | ||
no-security-framework.patch |