Skip to content

Quant.Infra.Net.Pro v1.8.3

Choose a tag to compare

@memoryfraction memoryfraction released this 30 Sep 01:34

English

Fixes: fresh Linux installs now show "Secure" in the browser out of the box.

  • Correct NSS trust flag (the root cause of "not secure"). The local CA was imported into the
    user's NSS database with the C,, trust flag, which does not mark a certificate as trusted for
    TLS. Chrome/Chromium therefore still showed https://127.0.0.1:8443 as "not secure" on first launch.
    The CA is now imported with the CT,CT,CT flag, so a new install is trusted for SSL immediately.
  • PEM export for certutil. The CA is now converted to PEM before the NSS import, which keeps the
    stored NSS entry valid (this also works around builds whose quant-ca.cer is DER).

中文

修复:全新 Linux 安装开箱即显示"安全"。

  • 正确的 NSS 信任标志("不安全"的根因)。 之前本地 CA 以 C,, 标志导入用户 NSS 库,该标志并未
    将证书标记为"受信任的 TLS 根",导致 Chrome/Chromium 首次访问 https://127.0.0.1:8443 仍显示
    "不安全"。现在以 CT,CT,CT 标志导入,新安装立即被信任。
  • PEM 导出。 导入 NSS 前先将 CA 转为 PEM,确保 NSS 条目有效(同时兼容 quant-ca.cer 为 DER 的构建)。