Changes

Jump to: navigation, search

CA/Additional Trust Changes

111 bytes added, 11:03, 19 October 2016
Clarify that the restrictions aren't implemented in NSS, but outside of NSS, at the Mozilla application level
==CNNIC==
Mozilla [https://blog.mozilla.org/security/files/2015/04/CNNIC-MCS.pdf recommends] not trusting any certificates issued by this CA after 1st April 2015. We have a [https://dxr.mozilla.org/mozilla-central/source/security/certverifier/CNNICHashWhitelist.inc whitelist of older certificates], and tools to generate it. The code implementing this restriction is [https://dxr.mozilla.org/mozilla-central/source/security/certverifier/NSSCertDBTrustDomain.cpp#753 in NSSthe Mozilla platform security code (PSM)], which is shared by the Mozilla applications (Firefox, Thunderbird, etc.).
Confirm
563
edits

Navigation menu