b9bb98cf49
This commit adds an option to replace libnssckbi with the p11-kit-trust[1] module. It makes all NSS application (like Firefox, Chromium, etc.) use the system trust store (/etc/ssl/certs/ in NixOS) and other PKCS#11 modules without ad-hoc configuration. This approach was first implemented in Fedora[2] and other distributions like Arch Linux, later. [1]: https://p11-glue.github.io/p11-glue/p11-kit/manual/trust-nss.html [2]: https://fedoraproject.org/wiki/Features/SharedSystemCertificates |
||
---|---|---|
.. | ||
3.44.nix | ||
3.53.nix | ||
85_security_load-3.44.patch | ||
85_security_load.patch | ||
ckpem.patch | ||
default.nix | ||
fix-cross-compilation.patch |