Closed Bug 575116 Opened 14 years ago Closed 14 years ago

Firefox 3.6.6 contains files which are not digitally signed

Categories

(Firefox :: General, defect)

x86
Windows Vista
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 489961

People

(Reporter: jeffrey_wilhelm, Unassigned)

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.70 Safari/533.4
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6 ( .NET CLR 3.5.30729)

The latest Firefox Build for 32-bit Windows (3.6.6) hosted on the Firefox front page contains PE files which are not digitally signed.  Specifically, the following 3 files are unsigned:

freebl3.dll
nssdbm3.dll
softokn3.dll

Installing unsigned files alongside the rest of the build is highly suspicious, and can lead to user confusion or even false positives from security software.

Reproducible: Always

Steps to Reproduce:
1. Download the 3.6.6 Firefox build from the following page - http://www.mozilla.com/en-US/firefox/firefox.html
2. Install the build on a Windows machine using the GUI
3. Right click on any of the 3 unsigned files (freebl3.dll, nssdbm3.dll, softokn3.dll) and select properties.
4. You will see that the digital signatures tab for the files is missing (indicating that they are not signed)
Actual Results:  
The digital signature information is not present for the files.

Expected Results:  
The files should be digitally signed.
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → DUPLICATE
ALL versions of Firefox 3.x have ALWAYS contained files that were not signed.
This is not a new phenomenon with 3.6.6.  The files you cited have NEVER been
signed.  Why is your product NOW suddenly unhappy about this?  

Those files may or may not ever be signed.  Your product should be accustomed
to this by now, IMO.
You need to log in before you can comment on or make changes to this bug.