Closed Bug 271695 Opened 20 years ago Closed 8 years ago

Automatic updating of trusted root authorities

Categories

(Core Graveyard :: Security: UI, enhancement)

Other Branch
enhancement
Not set
normal

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: bugzilla, Unassigned)

Details

From:
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_cmautorootupdt.mspx
"In Windows XP, you can use the Update Root Certificates function for this. When
you install Windows XP, Update Root Certificates is turned on by default. With
this feature turned on, if you are presented with a certificate issued by an
untrusted root authority, your computer will contact the Windows Update Web site
to see if Microsoft has added the CA to its list of trusted authorities. If it
has been added to the Microsoft list of trusted authorities, its certificate
will automatically be added to your trusted certificate store"

This is pretty smart I think. Perhaps the update.mozilla.org site could hold the
list of trusted root certificates and NSS could be made into handling such stuff?
This is an enhancement request for PSM, IMO.  
Assignee: wtchang → kaie
Component: Libraries → Client Library
Product: NSS → PSM
QA Contact: bishakhabanerjee
We should of course not get our list of trusted certs from Microsoft ;-)

Automatic updating of trusted root certs seems, in general, very reasonable to me.
This should not be limited to adding new authorities, but in addition could be
used to remove authorities that have turned out to be not trustworthy.

However, this feature would have to be carefully designed, to only allow the
mozilla.org site to drive the installation / removal of authority certs, and not
allow anybody else to do it.
Assignee: kaie → nobody
OS: Windows XP → All
Hardware: PC → All
Product: PSM → Core
QA Contact: ui
We might eventually do this with kinto, but for now updating the browser itself is sufficient (also, we have the blocklist, so we can revoke roots if we need to).
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → WORKSFORME
Product: Core → Core Graveyard
You need to log in before you can comment on or make changes to this bug.