What are CERTDB_INVISIBLE_CA and CERTDB_GOVT_APPROVED_CA used for?

Jeremy Rand <[email protected]> Fri, 7 Dec 2018 20:14:41 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============4765815728571663537==
Content-Type: multipart/signed; micalg=pgp-sha512;
 protocol="application/pgp-signature";
 boundary="tLLqFfpekP9u8OBKez2omT9k8wzgewBK8"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--tLLqFfpekP9u8OBKez2omT9k8wzgewBK8
Content-Type: multipart/mixed; boundary="OF4EpXW07FjhCPj0EqKR73ghRr10OlGQT";
 protected-headers="v1"
From: Jeremy Rand <[email protected]>
To: [email protected]
Message-ID: <[email protected]>
Subject: What are CERTDB_INVISIBLE_CA and CERTDB_GOVT_APPROVED_CA used for?

--OF4EpXW07FjhCPj0EqKR73ghRr10OlGQT
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

I was digging through the NSS source code, and I ran across two
undocumented trust flags: CERTDB_INVISIBLE_CA and CERTDB_GOVT_APPROVED_CA=
 .

As far as I can tell, CERTDB_INVISIBLE_CA seems to indicate that the UI
should hide the existence of the CA from the user, while
CERTDB_GOVT_APPROVED_CA seems to have something to do with crypto export
regulations.  I'm wondering if anyone can explain what exactly the
intended purpose of these flags is, and whether they actually have any
effect in any of the NSS software ecosystem (including Firefox, but also
including the NSS certificate verifier, any of the various NSS tools
distributed by Mozilla, and anything else that uses NSS that you're
aware of).  I can't think of any reason for CERTDB_INVISIBLE_CA to exist
(other than making it easier for backdoors to be stealthily inserted,
which I assume isn't the intended use case), and I'm also surprised that
CERTDB_GOVT_APPROVED_CA is a thing in 2018 since (as far as I know)
crypto export regulations haven't existed for a couple of decades.

Cheers,
--=20
-Jeremy Rand
Lead Application Engineer at Namecoin
Mobile email: [email protected]
Mobile OpenPGP: 2158 0643 C13B B40F B0FD 5854 B007 A32D AB44 3D9C
Send non-security-critical things to my Mobile with OpenPGP.
Please don't send me unencrypted messages.
My business email [email protected] is having technical issues at the
moment.


--OF4EpXW07FjhCPj0EqKR73ghRr10OlGQT--

--tLLqFfpekP9u8OBKez2omT9k8wzgewBK8
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEVB3fdzAraEcoBtkSs/LRZXhtZXAFAlwK1LcACgkQs/LRZXht
ZXCOrA/7Bcfewg2aJQFcdb2YKNJAzIx9jx3h+WMNuppUzrTH2r++6ekfpovghAZE
Rc0A9OOw96tqE+mdP7BM3hXNXz9N8tDMZ6hQHO36u9y6Vz3esRymJ5vk+39YOtmM
A0tCUzxgllRHap29FMbH1k5XqDERzjcgFSPaClDkO3CI6iqnJbIT3T83SrfCrZ1q
R9vHghD2YVFJFlB3mUJEDSAZ0x0a1V+2s9lzWMLhbtcIobN2Q7aTCxtcEDYgxi6X
nYmPe8VY560VVgZuLKOvvfJ2UhMsE+PJd+EX062QzzGgAzn02gKVyc+JR5wgARa6
6aO0ODeCTDC+AJn0rEfXDXCJind0TfI4J/GTRYATrFRksnJilUZxYhR7FH20xMfe
aEQ42A5crhjJyWJh3I5Y8v9kkw8QvBAh/yTP2NnAHyzPZdBvVoTDl7I/bpJItTir
bzcnTagtFJ2SCnnGIQuiiAtfZJDPPC9SBtO7mmsupJAlaZuFyDYIDlC1TIxeaFN4
Q09AdCXvyittDM9c7FFWceBoB8/VLDyvr2bG6muziRfB6NKR0c9QhZZCLY4tb4mK
kxqjMZbnLEOrKIRNty1yvP90xDzLMyM8YHl+g6s9f5DlsTJBTnsSWSFYNXu+Pchm
KTTkzURRIKo3LGjehyO5zIi1DS/t9TCo7DoTSCV9HhysB4sRegg=
=FPL/
-----END PGP SIGNATURE-----

--tLLqFfpekP9u8OBKez2omT9k8wzgewBK8--

--===============4765815728571663537==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security

--===============4765815728571663537==--