On Thu, Feb 27, 2025 at 9:31 AM Robert Moskowitz <rgm@xxxxxxxxxxxxxxx> wrote: > > On 2/27/25 8:17 AM, Barry wrote: > > > >> On 27 Feb 2025, at 10:39, Robert Moskowitz <rgm@xxxxxxxxxxxxxxx> wrote: > >> > >> But how to update the cert file? Which one is it or will the next firefox update replace it? > > I would have assumed that the cert is shipped with firefox itself. > > There is a signed trust list that every browser vendor provides. It > gets updated whenever a new cert is add. It possible is included in > each update even when not changed. See <https://wiki.mozilla.org/CA/Included_Certificates> and friends. And follow the link to the "... documented on a best effort basis [sic]", and pay attention to DistrustAfter. Browsers use DistrustAfter to include CAs that have been kicked out of the Root Store programs, like Entrust. See <https://wiki.mozilla.org/CA/Additional_Trust_Changes>. > But it is there, I just have to find the one that was installed when I > built the system and copy it over the old cruft I moved over. > > Tahar ElGamal, a student of Rivest at MIT, holds the patent (long > expired) on SSL and the approach of a trust list of root certs. He was > one of my mentors a few decades ago. His SSL got us off ground zero and > gave us a path for deploying X509 certs for trust-building. I have been > in countless discussions of the various approaches to trust. I myself > am the author of the Bridge CA model (circa '98) used in a few PKIs. > > This doesn't mean I cannot shoot myself in the foot at times, overlaying > the new list with an old one! Jeff -- _______________________________________________ users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue