Last modified: 2014-08-14 17:54:36 UTC
In a recent irc conversation {{citation needed}} it was determined that the requirement for people to have signed an NDA is bogus. The ability to sudo all commands should be restored for all members of the project.
That has been done because we want to deploy real SSL certificate on the HTTPS handlers (on beta cluster, that is nginx on the varnish instances): bug 48501. So I went with a sudoer group under_NDA. I lack knowledge about how SSL Certificate authority and certs work. There might be a way to have some custom SSL cert that we would not mind too much being stollen.
Making this change would essentially mean that we are abandoning the quest for installing commercially provided ssl certificates in beta and closing bug 48501 as WON'T FIX. We could still do something using self-signed certs of that is wanted/needed. I would like to hear from Antoine and Chris McMahon on this topic. I'd personally come down on the side of allowing more people to participate in beta in a meaningful way, but I'm willing to be told that I'm missing a bigger picture need.