Re: Trust bits for client auth
Richard Barnes <[email protected]> Wed, 10 Feb 2016 12:57:53 -0500
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAOAcki_PLTnBQdzjy8Lt-oCooOTVfTUgzt2Y2x45xiVGrebN_Q@mail.gmail.com> |
I happen to have been looking at this code today! It turns out (rather surprisingly) that the root is required to have the email trust bit. https://dxr.mozilla.org/mozilla-central/source/security/certverifier/CertVerifier.cpp?from=CertVerifier.cpp#248 (If someone wanted to file a bug to change that, I might be favorably disposed.) Skimming through certdata.txt, it looks like most of the included roots have this bit set. On Wed, Feb 10, 2016 at 12:30 PM, <[email protected]> wrote: > Does Firefox put any restriction on which roots are trusted to issue > client auth certs? Does the root require a particular trust bit? > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >