Changes

Jump to: navigation, search

CA/FAQ

140 bytes removed, 00:22, 14 July 2021
m
updates links
In some organizations administrators need to configure additional trusted CAs or override the trust settings of CAs on a system wide level, as required by local system environments or corporate deployments. For example, some organizations have their own in-house CA, and need to automate importing their root certificate(s) into NSS on their internal servers.
Here are some resources about this.Additional Information:* Adding Certificates for Firefox** [[CA:AddRootToFirefox | Add any root certificatea Root Certificate to Firefox]]** [https://addons.mozilla.org/en-us/firefox/addon/cacert-root-certificate/ Add CACert root only]* Adding Certificates to NSS for other applications
** [https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/tools/NSS_Tools_certutil certutil] -- a command-line utility that can be used to list, generate, modify, or delete certificates in the NSS root store.
*** [https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/tools#Tools_Information NSS Tools]
** For systems with Fedora and RHEL (6.5 and newer) see the manual page for update-ca-trust (man update-ca-trust)
** For systems with Ubuntu/Debian see the manual page for update-ca-certificates
* [https://wwwgroups.google.com/a/mozilla.org/en-US/about/forumsg/#dev-techsecurity-crypto policy Discussion forum] where you can ask questions and get answers from others who have done this
Confirm, administrator
5,526
edits

Navigation menu