Closed
Bug 1017262
Opened 11 years ago
Closed 11 years ago
Remove Code Signing trust bit from VeriSign Class 2 roots
Categories
(NSS :: CA Certificates Code, task)
NSS
CA Certificates Code
Tracking
(Not tracked)
RESOLVED
FIXED
3.16.3
People
(Reporter: rick_andrews, Unassigned)
References
Details
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20100101 Firefox/29.0 (Beta/Release)
Build ID: 20140506152807
Steps to reproduce:
Mozilla's trust store currently contains these certificates:
"VeriSign Class 2 Public PCA – G2"
SHA-1: B3:EA:C4:47:76:C9:C8:1C:EA:F2:9D:95:B6:CC:A0:08:1B:67:EC:9D
"VeriSign Class 2 Public PCA - G3"
SHA-1: 61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
Their trust bits are Email, Code. Please remove the "Code" trust bit from both roots.
Actual results:
n/a
Expected results:
n/a
Updated•11 years ago
|
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Updated•11 years ago
|
Assignee: kwilson → nobody
Product: mozilla.org → NSS
Version: other → trunk
Updated•11 years ago
|
Summary: Remove trust bits from VeriSign Class 2 roots → Remove Code Signing trust bit from VeriSign Class 2 roots
Updated•11 years ago
|
Comment 1•11 years ago
|
||
A Test Build with these changes has been created as part of Bug #1021967.
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-394c2eeb9793/
I have already checked/tested it, but you are all welcome to check it too.
Comment 2•11 years ago
|
||
fixed as part of bug 1021967
Status: ASSIGNED → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Target Milestone: --- → 3.16.3
Comment 3•11 years ago
|
||
This comment is purely for documenting something I looked up.
The code signing trust bit removal from
sha1 = B3:EA:C4:47:76:C9:C8:1C:EA:F2:9D:95:B6:CC:A0:08:1B:67:EC:9D
had been requested in bug 986005, too, so this bug is a half-duplicate of that other bug.
This is a 1024-bit key certificate.
The other certificate with
sha1 = 61:EF:43:D7:7F:CA:D4:61:51:BC:98:E0:C3:59:12:AF:9F:EB:63:11
has a 2048-bit key, which means this trust bit removal wasn't done as part of phasing out 1024-bit keys.
You need to log in
before you can comment on or make changes to this bug.
Description
•