3 ms·
I disagree. OS certificate stores often come with the political baggage of the OS manufacturer. When a Chinese Gov't CA was found to have engaged in fraudulent
by intsunny 7y ago
I disagree.
OS certificate stores often come with the political baggage of the OS manufacturer. When a Chinese Gov't CA was found to have engaged in fraudulent behavior [0] Google and Firefox were quick to revoke/remove the CA cert from their products. Apple and Microsoft did not do the same, likely because they do not want to upset the Chinese Gov't. (IIRC Iphone users cannot even manually revoke CA's on their own phones.)
[0] https://en.wikipedia.org/wiki/China_Internet_Network_Information_Center#Fraudulent_certificates https://en.wikipedia.org/wiki/China_Internet_Network_Informa...
- lenkite 7y agoThen FireFox has made the deliberate choice of excluding millions of users. There are millions of users who use identity management solutions where user-certs and priv-keys are put into the OS store of their devices. Using the OS secure-store should be a preference option. The folks who don't want to use the "political baggage" of the OS manufacturer - as you put it - can continue to use their pristine gardens.
- worble 7y agoI've never used this personally, but it is a preference option? https://serverfault.com/questions/722563/how-to-make-firefox-trust-system-ca-certificates https://serverfault.com/questions/722563/how-to-make-firefox... Or am I totally misunderstanding this and that's something totally different?
- lenkite 7y agoI didn't know about this option - thanks. This option basically uses the OS cert store for server certificates, which is one part of the story. Now, if they also did this for client-certificates then all the folks in companies that use corporate certificate-based single-sign-on can use FireFox!