Re: Epiphany 3.14 will block untrusted TLS connections
Michael Catanzaro <[email protected]> Fri, 21 Nov 2014 10:36:10 -0600
| Newsgroups | gmane.comp.gnome.apps.epiphany |
|---|---|
| Organization | GNOME |
| Message-ID | <1416587770.2650.10.camel@lumiose-city> |
On Mon, 2014-09-08 at 09:48 -0500, Michael Catanzaro wrote: > 2) The latest upstream version of ca-certificates removes several root > certs with 1024-bit RSA keys, even though valid certificates issued by > those certs are still in use [2]. Fedora 21 already has the latest > version of ca-certificates, and it has broken popular web sites, > including as amazon.com and kickstarter.com, in Epiphany. Please > consider delaying any planned update of this package for a few months, > until the fallout [3] has passed. Distros shipping GNOME 3.14 should > strongly consider sticking with the previous release of > ca-certificates, > from March 2014. Hi GNOME distributors, Fedora has documented at [1] a list of CA certificates removed by Mozilla that are still required for glib-networking to be compatible with many web sites. It's now safe to update your ca-certificates package if you take care to restore these legacy certificates with their original trust bits. If you choose to update ca-certificates without ensuring that these certificates remain installed with their original trust bits, we will not handle TLS-related bug reports from your distro. [1] https://fedoraproject.org/wiki/CA-Certificates _______________________________________________ epiphany-list mailing list [email protected] https://mail.gnome.org/mailman/listinfo/epiphany-list
signature.asc
(application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAABAgAGBQJUb2n6AAoJEH9xtkJ5NjKYJ2YH/R62XN1UygvmPw5Xe65YmWgX rP8uWlDbQNya1Yum4i3714rPKzAo1Y3T7QYjTAfrWmrq9em4WFKeCwIQ5J5i6v1F y9s5jFUxvy4Epafzqudxw5KrpsvsOHDJTeCc1VIxKyflL5PUR6BCkEQ58F2zQUJM 2RoyJl9vetsjADjHByaDwmaHJzGdo2yeLkGOYhq66NGpRY/aSDEI0eNbZoYbCwI1 7mr22zBn4cRDtCmYysO81BzevOUmFInRjEhNc7FaOgWrxtfFdndDvf5kDHzAtxsB MJ12fsEThGF01RL2nvEwpsB0AlTFMXHX2Z/liSqF8q4v+hcAtI7JKz0WWvA9Cjg= =2wTI -----END PGP SIGNATURE-----