Skip to content
This repository was archived by the owner on Feb 20, 2023. It is now read-only.
This repository was archived by the owner on Feb 20, 2023. It is now read-only.

Revoked certificates not trapped #20226

@mrandreastoth

Description

@mrandreastoth

Firefox Nightly (and most likely all editions) does not trap revoked certificates when such a site is visited (test facility to be provided in an update). This is highly concerning since the revolution of a certificate should be brought to the user's attention as it can indicate some concerning reasons why this was done, such as a previously OK site having gone rogue for whatever reason. Note that I have yet to find a browser, Firefox or otherwise, that actually handles revoked certificates. However, just because everyone fails does not mean Firefox should copy a bad habit, a habit that, according to the following link, goes way back...

https://www.zdnet.com/article/major-linux-rpm-problem-uncovered/

My suggestion: make all editions of Firefox warn on revoked certificates by default.

┆Issue is synchronized with this Jira Task

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs:triageIssue needs triage🐞 bugCrashes, Something isn't working, ..

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions