Two certificates with the same nickname can be imported

UNCONFIRMED
Unassigned

Status

NSS
Tools
UNCONFIRMED
3 years ago
3 years ago

People

(Reporter: chenyt.cs.sjtu, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment)

(Reporter)

Description

3 years ago
Created attachment 8542315 [details]
certificates_imported_with_same_nickname.zip

User Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36

Steps to reproduce:

(1) one root certificate is imported into the firefox certificate database. 
Certificate Manager -> Authorities-> Import ... (Import rootCA_key_cert.pem)
(2) another certificate is imported as a server certificate
Certificate Manager -> Servers -> Import...(Import 87.98.168.164.pem)
(3) Open a terminal and list all the certs in the database
certutil -L -d ...



Actual results:

The two certificates suddenly have the same nickname and thus I cannot use the certutil to modify the Trust Attributes as I like. I have to modify their attributes using the firefox Certificate Manager. In fact some other certificates with the same nickname may be rejected.


Expected results:

One certificate needs to be rejected when the second certificate is imported and some error messages need to be reported.
You need to log in before you can comment on or make changes to this bug.