Closed Bug 1147287 Opened 9 years ago Closed 9 years ago

Verify self signed certificates using fingerprint

Categories

(Firefox :: Untriaged, defect)

36 Branch
x86_64
Linux
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1012879

People

(Reporter: lorenzo.keller, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:36.0) Gecko/20100101 Firefox/36.0
Build ID: 20150220131007

Steps to reproduce:

Navigate to a SSL website that is using a self-signed certificate.


Actual results:

Firefox displays an error message that suggest that something is wrong.


Expected results:

Firefox prompts the user to enter an "authentication code" for the website that the user should have received from the website owner. This can for instance be obtained by the user via snail mail, SMS, QR codes, over the phone.... 

Once the user confirms the input, Firefox checks that the code entered matches the fingerprint of the received certificate. If it is the case it adds the certificate to a local store of "manually authenticated" certificates until the certificate expires. Sites verified in this fashion gets are marked with a special badge (similar to what is done for EV certificates but with a different color to show the higher security level).

Certificates accepted in this way should always supersede CA validated certificates (and a warning should be displayed if a CA validated certificate is encountered).

The proposed approach has the following advantages:

 - It becomes easy for a normal user to properly validate a self signed certificate
 - It remains hard to convince a user to blindly accept a self signed certificate
 - It becomes possible to protect users from fraudulent certificates issued by accident by CAs
Hi Lorenzo,

Thanks for filing the bug. However, it looks like a similar idea was filed as Bug 1012879, so I'm marking this as a duplicate.
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: