4 ms·
"FF only validates the End-entity is within date range" No, this was disabled back in 2016. The technical report briefly had this worded wrong, sorry if you re
by sciurus 7y ago
"FF only validates the End-entity is within date range"
No, this was disabled back in 2016. The technical report briefly had this worded wrong, sorry if you read it before it was corrected.
"what is the point of the signing system in the first place?"
Like the technical report describes, things like "monitoring add-ons not hosted on AMO, blocklisting malicious add-ons, providing cryptographic assurance by chaining add-ons to the Mozilla root."
(Disclosure: I work for Mozilla)
- groovybits 7y agoSo, the intended behavior is that FF does not check any Add-on related cert for a valid date range? In that case, what prevents an insider threat of a Mozilla employee signing malicious add-ons with an out-of-date cert?
- yzmtf2008 7y agoWhat prevents an insider threat of a Mozilla employee signing malicious add-ons with a not out-of-date cert?
- michaelt 7y agoWhen you sign software with certificates that can expire, you run into the problem that software can stop working with no change on the user's end whatsoever. And of course, the shorter the expiry on code-signing certificates, the worse this problem becomes. The solution for systems like Java and Authenticode is for Certificate Authorities to also offer a 'Trusted Timestamping' service, which certifies that the software existed at a time when the code-signing certificate was valid. In Java's case, as the CA providing the timestamp is already trusted issue code-signing certificates with arbitrary dates, this doesn't add any new trusted parties.