Talk:Extension Manager:Addon Update Security: Difference between revisions

(Question about providing updates without SSL)
(→‎Update Scenarios: XPI signing)
Line 43: Line 43:


--[[User:Grimholtz|Grimholtz]] 12:18, 9 July 2007 (PDT)
--[[User:Grimholtz|Grimholtz]] 12:18, 9 July 2007 (PDT)
1. I already sign my XPI files with signtool and my code signing cert which creates the META files with the hash embedded. Will there be a check to see if that is used instead having to also sign the updates.rdf file?
2. If that wouldn't be possible then could the same cert also generate a new updates.rdf file that includes the hash. I could create a new build script to do just that and it would still make everything pretty painless making a release.
--[[User:Sgrayban|Sgrayban]] 11:48, 18 July 2007 (PDT)


== No-SSL downloads ==
== No-SSL downloads ==
1

edit