Windows platform support for trusting enterprise roots
Categories
(Core :: Security: PSM, defect)
Tracking
()
People
(Reporter: keeler, Assigned: keeler)
References
Details
(Whiteboard: [psm-assigned])
Attachments
(1 file)
| Assignee | ||
Comment 1•10 years ago
|
||
| Assignee | ||
Comment 2•10 years ago
|
||
Comment 3•10 years ago
|
||
| Assignee | ||
Comment 4•10 years ago
|
||
| Assignee | ||
Comment 5•10 years ago
|
||
| Assignee | ||
Updated•10 years ago
|
Updated•10 years ago
|
Comment 6•10 years ago
|
||
Updated•10 years ago
|
Comment 7•10 years ago
|
||
Comment 8•10 years ago
|
||
| Assignee | ||
Comment 9•10 years ago
|
||
| Assignee | ||
Comment 10•10 years ago
|
||
| Assignee | ||
Comment 11•10 years ago
|
||
| Assignee | ||
Comment 12•10 years ago
|
||
Comment 13•10 years ago
|
||
Comment 14•10 years ago
|
||
Comment 15•10 years ago
|
||
Comment 16•10 years ago
|
||
| Assignee | ||
Comment 17•10 years ago
|
||
| Assignee | ||
Comment 18•10 years ago
|
||
| Assignee | ||
Comment 19•10 years ago
|
||
| Assignee | ||
Comment 20•10 years ago
|
||
| Assignee | ||
Comment 21•10 years ago
|
||
Comment 22•10 years ago
|
||
Comment 23•10 years ago
|
||
| bugherder | ||
Comment 26•10 years ago
|
||
Comment 27•10 years ago
|
||
Updated•10 years ago
|
| Assignee | ||
Updated•10 years ago
|
Comment 28•10 years ago
|
||
Comment 29•10 years ago
|
||
Comment 30•10 years ago
|
||
Comment 31•10 years ago
|
||
Comment 32•10 years ago
|
||
Comment 33•10 years ago
|
||
Comment 34•10 years ago
|
||
Comment 35•10 years ago
|
||
Comment 36•10 years ago
|
||
Comment 37•10 years ago
|
||
Comment 38•10 years ago
|
||
Comment 39•10 years ago
|
||
Comment 40•10 years ago
|
||
Comment 41•10 years ago
|
||
Comment 42•10 years ago
|
||
| Assignee | ||
Comment 44•10 years ago
|
||
Comment 45•10 years ago
|
||
Comment 46•10 years ago
|
||
Comment 47•10 years ago
|
||
Comment 48•10 years ago
|
||
Comment 49•10 years ago
|
||
Comment 50•10 years ago
|
||
Comment 51•10 years ago
|
||
Comment 52•10 years ago
|
||
Comment 53•9 years ago
|
||
Comment 54•9 years ago
|
||
| Assignee | ||
Comment 55•9 years ago
|
||
Comment 56•9 years ago
|
||
| Assignee | ||
Comment 57•9 years ago
|
||
Comment 58•9 years ago
|
||
Comment 59•9 years ago
|
||
Comment 60•9 years ago
|
||
Comment 61•9 years ago
|
||
Comment 62•9 years ago
|
||
Comment 63•9 years ago
|
||
Comment 64•9 years ago
|
||
Comment 65•9 years ago
|
||
Comment 66•9 years ago
|
||
| Assignee | ||
Comment 67•9 years ago
|
||
Comment 68•9 years ago
|
||
Comment 69•9 years ago
|
||
| Assignee | ||
Comment 70•9 years ago
|
||
Comment 71•9 years ago
|
||
Comment 74•9 years ago
|
||
Comment 75•7 years ago
|
||
Comment 76•7 years ago
|
||
| Assignee | ||
Comment 77•7 years ago
|
||
Comment 78•7 years ago
|
||
This is highly dangerous.
It makes our management of root CAs much more difficult. See e.g. Symantec case, the ongoing DarkMatter discussion of the inclusion criteria, etc. The entire discussion is about whether or not to include certain CAs. If you wholesale include all CAs from Windows, you defer the discussion to Microsoft and make the entire Root CA policy that we have completely moot.
https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/
The way I see it, this effort is in direct contradiction to our established root CA policy and rules.
Comment 79•7 years ago
|
||
(In reply to Ben Bucksch (:BenB) from comment #78)
If you scroll up and read the rest of the thread you'll see those concerns are already addressed. This is a feature that can be optionally enabled for users (like myself) who need it. Without it, it's far more difficult to use Firefox in the enterprise.
Comment 80•7 years ago
|
||
(In reply to Ben Bucksch (:BenB) from comment #78)
Ben,
I don't see how this changes the root CA policy. This allows those who MUST manage these things manage a single list instead of multiple lists. It is almost a requirement for Enterprise use of Firefox.
I have to know what root CAs are trusted no matter what tool a user is using. So I have to manage the MS Certificate Store very carefully. I want my Mozilla tools to use this same very carefully managed list, without having to manage it all over again. This feature allows me to do that without altering the configuration of those users who choose to have separate certificate stores.
Description
•