Re: On the future of <keygen> and application/x-x509-*-cert MIME handling

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.security,gmane.comp.mozilla.devel.platform
Message-ID <[email protected]>
On Thursday 30 July 2015 14:32:01 Richard Barnes wrote:
> On Thu, Jul 30, 2015 at 6:53 AM, Hubert Kario <[email protected]> wrote:
> > On Wednesday 29 July 2015 16:35:41 David Keeler wrote:
> > > [cc'd to dev-security for visibility. This discussion is intended to
> > > happen on dev-platform; please reply to that list.]
> > > 
> > > Ryan Sleevi recently announced the pre-intention to deprecate and
> > > eventually remove support for the <keygen> element and special-case
> > > handling of the application/x-x509-*-cert MIME types from the blink
> > > platform (i.e. Chrome).
> > > 
> > > Much, if not all, of that reasoning applies to gecko as well.
> > > Furthermore, it would be a considerable architectural improvement if
> > > gecko were to remove these features (particularly with respect to e10s).
> > > Additionally, if they were removed from blink, the compatibility impact
> > > of removing them from gecko would be lessened.
> > > 
> > > I therefore propose we follow suit and begin the process of deprecating
> > > and removing these features. The intention of this post is to begin a
> > > discussion to determine the feasibility of doing so.
> > 
> > because pushing people to use Internet Explorer^W^W Spartan^W Edge in
> > enterprise networks is a good plan to continue loosing market share for
> > Mozilla products! /s
> > 
> > lack of easy, cross-application certificate deployment is the _reason_ for
> > low
> > rates of deployment of client certificates, but where they are deployed,
> > they
> > are _critical_
> 
> <keygen> doesn't help you with cross-application deployment.  After all, IE
> doesn't support it.

and how removing <keygen> makes the situation better?

yes, Firefox doesn't deploy to system cert store (by default), but it's a bug 
in Firefox, not a feature
-- 
Regards,
Hubert Kario

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJVu1VJAAoJEJKo0bgB0vX140oP/A0K3jaAg75CNUORLOLf6Heo
XMgFplbQnTSsI8Om9Krnx3uZHC3GUF5OjpQ1+658VVa1INo6ebpVYqUArQw925kr
LHl3p5Gy4COEJy28EALC1LU9tP8xzdm6KnOZQlKHVMvLWXvLrwJCYt8oh7nE0yVT
qSXWB+8plTW4FYdhAPlhjJ9EWvBR8qe0OU1rQHyanIQ0Y2a7x6lDwl86/mR1f1Gq
N9+uV/rUX5Bn6s84hRogIdAvZ2ghtcWB50lN0C9ISZ48VXJWGntZY/aWRzzLK8py
+yR5MZi/fwK/qns23WfnGMnoiZZcFMvfsMRMI5uYW5Vo6Wa308zoqHCITXOGXNqO
uUbNzCOk0ZoIH92O1/2xLgXjBL3PwyXDVeyZBt6rn/CwiF16ojy0Pkt7LXP8a2Ye
GAVQczoT0ydKIzM2X1fXmKwM4CX3B7FiXqLbMNuzxhPvoWGm1kTiC2rfdHinzSaw
X8zv9rEdPmMAsgkx9Mx1/U46eXzXY7AY6PjQumdisBVFkh4u0YI5ROJqcNBwRJ8q
STz5eiG99stVNv8XmAt1mIP7uD2NYLDmkbi2rmVED+N//n2kEoI6yQJeIVECEZMt
k8BYXQl7JP0OPZ+PtPjNLVhVe9m3JwxsSKSyspqyCxObWB1vF3x+KuzqfjX4CbL2
YRo4PAOHnaKW/fWkZTCX
=zR6D
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.