Re: Trust bits for client auth

Richard Barnes <[email protected]> Wed, 10 Feb 2016 12:57:53 -0500
Newsgroups gmane.comp.mozilla.security
Message-ID <CAOAcki_PLTnBQdzjy8Lt-oCooOTVfTUgzt2Y2x45xiVGrebN_Q@mail.gmail.com>
I happen to have been looking at this code today!  It turns out (rather
surprisingly) that the root is required to have the email trust bit.

https://dxr.mozilla.org/mozilla-central/source/security/certverifier/CertVerifier.cpp?from=CertVerifier.cpp#248

(If someone wanted to file a bug to change that, I might be favorably
disposed.) Skimming through certdata.txt, it looks like most of the
included roots have this bit set.

On Wed, Feb 10, 2016 at 12:30 PM, <[email protected]> wrote:

> Does Firefox put any restriction on which roots are trusted to issue
> client auth certs? Does the root require a particular trust bit?
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>