Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] firefox SSL certs
- Date: Mon, 12 Sep 2011 13:47:36 +0900
- From: "Stephen J. Turnbull" <stephen@example.com>
- Subject: Re: [tlug] firefox SSL certs
- References: <4E6D3A61.6020409@example.com> <87sjo2pr6d.fsf@example.com> <4E6D5C1C.8050904@example.com> <87pqj6pk0k.fsf@example.com> <7ECF7587-4624-4C07-BDA1-548637F42171@example.com>
Philipp Wollermann writes: Thanks for the correction on the meaning of the unintelligible link names. > > Of course what this means is that ultimately you trust Mozilla > > .... > Mozilla, Debian and all others recently pushed an urgent security > update which removes the root certificate of the DigiNotar CA from > the trust store (aka /etc/ssl/certs). Sure, but there's a fair amount of controversy about whether they're strict enough. A similar incident happened with Comodo, but their certificate was not removed because in the judgment of the Mozilla team they responded "appropriately" -- but some people disgree. And as one of the Mozilla team pointed out inadvertantly, except for Comodo (known to do a good job by Mozilla standards) and DigiNotar (the reverse), all the other agencies are either doing a good job or better at hiding their flaws than DigiNotar ... and neither we nor Mozilla know which is true for any given agency. So what it comes down to is most people just trust Mozilla (and it's widespread; utilities like curl also "trust" Mozilla). I don't see a practical alternative, but users should be aware that that is what they are doing. > See this security advisory: http://www.debian.org/security/2011/dsa-2299 > > By the way, all SSL certificates in /etc/ssl/certs are supplied via > this package: *sigh* Putting the hashes in that directory is user-unfriendly organization.
- References:
- [tlug] firefox SSL certs
- From: Darren Cook
- [tlug] firefox SSL certs
- From: Stephen J. Turnbull
- Re: [tlug] firefox SSL certs
- From: Darren Cook
- Re: [tlug] firefox SSL certs
- From: Stephen J. Turnbull
- Re: [tlug] firefox SSL certs
- From: Philipp Wollermann
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] firefox SSL certs
- Next by Date: [tlug] Can I get someone to hold my hand with all this oAuth stuff?
- Previous by thread: Re: [tlug] firefox SSL certs
- Next by thread: [tlug] Can I get someone to hold my hand with all this oAuth stuff?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links