(address . guix-patches@gnu.org)
Three packages depend directly on nss-certs: ldns, pypy3, and icedtea6.
This is a problem because certificates expire. When that happens, the
features of these programs that use X.509 certificates will stop
working. Instead, packages should look up certificates at run-time in
unversioned and well-known locations such as /etc/ssl/certs or via
environment variables like $SSL_CERT_DIR.
I'll send a patch removing the dependency from ldns.
pypy3 does not build anyways because its runpath cannot be successfully
validated, but I will investigate anyways after disabling the runpath
validator.
Icedtea6 is a very complex package. I assume it depends on the
certificates directly for a good reason, but I would still appreciate
some feedback on it.
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAmHBIY8ACgkQJkb6MLrK
fwhFrg//RRKMHSBGI7wRv3PGE73PQHjr5BLEG8UOS+9B+L5bCQfNRaRgAC2Qz9w6
YmQahn4eX//CfAcysnmxSsjGbPI+JAMSKT+wPKos7KMJHlpB0bEmEF6JPcHg4FoF
iEgDhRqQu/CVXnhBIHCVa85jqEdjgugkPnO/wbeNqLN/DTg1noXtFSrj/xwwVHud
t+2vvjoBb89p6NXBjDWuw9nNExrVD8XV1Jqz0H6AKRarUSvcEgAcopKbC+Ma816h
f/UBzd/BXlxncNT/8zssq5xW+SsIYxWwVgRVjV6ckX2/707WVJzine6eoe+v4tEn
O6DYbtnIwxOquY0njnvM4lxgnKM3jVeNzVqrWjKuUCKOypgIE8rbkYkwPR4csbaA
W26r7FZXA5kn2cb7RqlalATLoc18n5y/yaSeFSsw+TVMhd46Wx8GjCENvnQvRr2t
1L1xH4FcGcoVs/GmEVN9MOB+z0g8+H48MiWAR73F5CayJVaocrFYN/PWDHShEFcy
WHmecWeyvws9ra+zjKq5opBnzj+QOs/aSP3m7lARvPPta8DlpL11iunDamtWnkDV
A+XTyvauqFPojR5+M2uzHhfl/TC5/RGH9Yr7p1ifCDMb4/TxbrMgFJLIjzprnHyI
czfGQnonIcPvT6lhMzCKRch+lWeuwCAsGCPUs18Gk8CyJkuSYIg=
=19Um
-----END PGP SIGNATURE-----