#1037036 ITP: autogram -- eIDAS-compliant document signing tool

#1037036#5
Date:
2023-06-02 11:28:56 UTC
From:
To:
* Package name    : autogram
  Version         : 1.99.10
  Upstream Contact: Jakub Ďuraš, Slovensko.Digital et al.
* URL             : https://github.com/slovensko-digital/autogram
* License         : EUPL 1.2
  Programming Lang: Java
  Description     : eIDAS-compliant document signing tool

Autogram is a cross-platform (Windows, MacOS, Linux) desktop JavaFX
application to sign documents accordancing to the eIDAS standard.
The user can use it to sign files directly, or the application can be
easily integrated into your own (web) information system using the
HTTP API.

#1037036#12
Date:
2023-06-02 18:13:01 UTC
From:
To:
The documentation hints at the fact that this application works only in
conjunction with Slovenian eIDs.

This (current?) limitation should be mentioned in the short and long
descriptions.

Regards,

#1037036#17
Date:
2023-06-02 18:42:30 UTC
From:
To:
Yes, right. Common lapsus lingue, isn't it? :)

The README on GitHub says:

 > Momentálne podporujeme na Slovensku bežne používané karty
 > a ich ovládače:
 >
 > * občiansky preukaz (eID klient)
 > * I.CA SecureStore
 > * MONET+ ProID+Q
 > * Gemalto IDPrime 940
 >
 > Doplniť ďalšie je pomerne ľahké pokiaľ používajú PKCS#11.

I read this as "Support for other kinds of eIDs is _possible and easy_
as long as they support PKCS#11, but _not automatic_". Am I reading this
wrong?

Regards,

#1037036#22
Date:
2023-06-02 18:25:41 UTC
From:
To:
Hi,

It's Slovak, not Slovenian.

It does in fact work with anything, as long as has a PKCS #11 provider.

#1037036#27
Date:
2023-06-04 08:53:38 UTC
From:
To:
Hi,

Well, I suspect they want to be on the safe side, but OTOH I have not verified it. Given that some of the Autogram’s dependencies are still not in Debian, I reckon this can either be solved upstream by the time the package is ready, or I can add a disclaimer to the package description.