Closed
Bug 1939086
Opened 1 year ago
Closed 11 months ago
Remove the S/MIME Trust Bit from the Security Communication ECC RootCA1 root cert
Categories
(NSS :: CA Certificates Code, enhancement)
NSS
CA Certificates Code
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: cainfo, Assigned: djackson)
References
Details
(Whiteboard: Removed email trust bit in NSS 3.108 and FF 136)
Attachments
(1 file)
No description provided.
| Reporter | ||
Comment 1•1 year ago
|
||
- Subject/Issuer field values in the root certificate to be changed
Issuer: C=JP, O=SECOM Trust Systems CO.,LTD., CN=Security Communication ECC RootCA1
Subject: C=JP, O=SECOM Trust Systems CO.,LTD., CN=Security Communication ECC RootCA1 - SHA256 Fingerprint of the certificate to be changed
E74FBDA55BD564C473A36B441AA799C8A68E077440E8288B9FA1E50E4BBACA11
https://crt.sh/?q=E74FBDA55BD564C473A36B441AA799C8A68E077440E8288B9FA1E50E4BBACA11 - Specify the change to be made
Security Communication ECC RootCA1 is a Root CA specifically for TLS Servers CAs.
Therefore, please disable only the Trust bit for "Secure Email." - Reason for requesting this change
During the construction phase of Security Communication ECC RootCA1, we considered it as a multi-purpose Root CA.
However, it is now a Root CA dedicated solely to TLS server certificates.
Since we do not plan to construct any subordinate S/MIME CAs in the future, please disable the Trust bit for "Secure Email." - Impact that the change may have on Mozilla users
There is no impact to Mozilla users.
Best Regards,
ONO, Fumiaki
SECOM Trust Systems Co., Ltd.
Updated•11 months ago
|
Assignee: nobody → bwilson
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(bwilson)
Comment 2•11 months ago
|
||
For this CA,
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR needs to be changed to:
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
Thanks,
Ben
Flags: needinfo?(bwilson)
Updated•11 months ago
|
Assignee: bwilson → djackson
| Assignee | ||
Comment 3•11 months ago
|
||
| Assignee | ||
Comment 4•11 months ago
|
||
Status: ASSIGNED → RESOLVED
Closed: 11 months ago
Resolution: --- → FIXED
Updated•11 months ago
|
Whiteboard: Removed email trust bit in NSS 3.108 and FF 136
You need to log in
before you can comment on or make changes to this bug.
Description
•