Quant.Infra.Net.Pro v1.8.3
English
Fixes: fresh Linux installs now show "Secure" in the browser out of the box.
- Correct NSS trust flag (the root cause of "not secure"). The local CA was imported into the
user's NSS database with theC,,trust flag, which does not mark a certificate as trusted for
TLS. Chrome/Chromium therefore still showedhttps://127.0.0.1:8443as "not secure" on first launch.
The CA is now imported with theCT,CT,CTflag, so a new install is trusted for SSL immediately. - PEM export for
certutil. The CA is now converted to PEM before the NSS import, which keeps the
stored NSS entry valid (this also works around builds whosequant-ca.ceris DER).
中文
修复:全新 Linux 安装开箱即显示"安全"。
- 正确的 NSS 信任标志("不安全"的根因)。 之前本地 CA 以
C,,标志导入用户 NSS 库,该标志并未
将证书标记为"受信任的 TLS 根",导致 Chrome/Chromium 首次访问https://127.0.0.1:8443仍显示
"不安全"。现在以CT,CT,CT标志导入,新安装立即被信任。 - PEM 导出。 导入 NSS 前先将 CA 转为 PEM,确保 NSS 条目有效(同时兼容
quant-ca.cer为 DER 的构建)。