Re: Epiphany 3.14 will block untrusted TLS connections

Michael Catanzaro <[email protected]> Fri, 21 Nov 2014 10:36:10 -0600
Newsgroups gmane.comp.gnome.apps.epiphany
Organization GNOME
Message-ID <1416587770.2650.10.camel@lumiose-city>
On Mon, 2014-09-08 at 09:48 -0500, Michael Catanzaro wrote:
> 2) The latest upstream version of ca-certificates removes several root
> certs with 1024-bit RSA keys, even though valid certificates issued by
> those certs are still in use [2]. Fedora 21 already has the latest
> version of ca-certificates, and it has broken popular web sites,
> including as amazon.com and kickstarter.com, in Epiphany. Please
> consider delaying any planned update of this package for a few months,
> until the fallout [3] has passed. Distros shipping GNOME 3.14 should
> strongly consider sticking with the previous release of
> ca-certificates,
> from March 2014.

Hi GNOME distributors,

Fedora has documented at [1] a list of CA certificates removed by
Mozilla that are still required for glib-networking to be compatible
with many web sites. It's now safe to update your ca-certificates
package if you take care to restore these legacy certificates with their
original trust bits.

If you choose to update ca-certificates without ensuring that these
certificates remain installed with their original trust bits, we will
not handle TLS-related bug reports from your distro.

[1] https://fedoraproject.org/wiki/CA-Certificates

_______________________________________________
epiphany-list mailing list
[email protected]
https://mail.gnome.org/mailman/listinfo/epiphany-list
signature.asc (application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAABAgAGBQJUb2n6AAoJEH9xtkJ5NjKYJ2YH/R62XN1UygvmPw5Xe65YmWgX
rP8uWlDbQNya1Yum4i3714rPKzAo1Y3T7QYjTAfrWmrq9em4WFKeCwIQ5J5i6v1F
y9s5jFUxvy4Epafzqudxw5KrpsvsOHDJTeCc1VIxKyflL5PUR6BCkEQ58F2zQUJM
2RoyJl9vetsjADjHByaDwmaHJzGdo2yeLkGOYhq66NGpRY/aSDEI0eNbZoYbCwI1
7mr22zBn4cRDtCmYysO81BzevOUmFInRjEhNc7FaOgWrxtfFdndDvf5kDHzAtxsB
MJ12fsEThGF01RL2nvEwpsB0AlTFMXHX2Z/liSqF8q4v+hcAtI7JKz0WWvA9Cjg=
=2wTI
-----END PGP SIGNATURE-----