Closed Bug 720478 Opened 12 years ago Closed 12 years ago

add "cross root" intermediate to production *.s.m.c, *.browserid.org certificates

Categories

(Cloud Services :: Operations: Deployment Requests - DEPRECATED, task)

task
Not set
normal

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: Atoll, Assigned: Atoll)

References

Details

We discovered that Android 2.2, a platform we must support, does not have the Geotrust root CA, and so this breaks Native Sync.

This is fixed by adding a second intermediate, the Geotrust "cross root", that chains all the way back to the classic old Equifax CA that's supported by Android 2.2.

See bug 717692 for how we discovered this. Stage testing has confirmed so far that adding the second intermediate resolves the SSL issues for 2.2 devices and has no impact on newer devices.

Scheduled for 20110124 maintenance window.
Component: Operations → Operations: Deployment Requests
QA Contact: operations → operations-deploy-requests
> See bug 717691

corrected
\o/
Blocks: 717691
OS: Mac OS X → All
Hardware: x86 → All
expanding to cover *.browserid.org as well, since we've confirmed it in stage.
Summary: add "cross root" intermediate to production *.s.m.c certificate → add "cross root" intermediate to production *.s.m.c, *.browserid.org certificates
deployed to prod today, *.browserid.org and *.s.m.c.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
And verified by QA.
A separate issue was filed specifically related to BrowserID:
Bug 720860 - https://myapps.mozillalabs.com/jsapi/include.js causes Cert Warnings in Android 2.2
Status: RESOLVED → VERIFIED
(In reply to James Bonacci [:jbonacci] from comment #5)
> And verified by QA.
> A separate issue was filed specifically related to BrowserID

More precisely, related to the Labs site used by QA for BrowserID testing.
You need to log in before you can comment on or make changes to this bug.