3 ms·
A big one for me (covered in the release notes): "Experimental support for using client certificates from the OS certificate store can be enabled on macOS by s
by ned_roberts 6y ago
A big one for me (covered in the release notes):
"Experimental support for using client certificates from the OS certificate store can be enabled on macOS by setting the preference security.osclientcerts.autoload to true."
This allows Firefox to work with my company's BeyondCorp implementation. I was forced to use Chrome before.
- majewsky 6y agoAwesome. Any word on whether this also applies to Windows? (Asking for a company-issued notebook.)
- bronxasaur 6y agoOn Windows, you should be able to set `security.enterprise_roots.enabled` to true. Might have to restart Firefox for it to recognize.
- U8dcN7vx 6y agoEnterprise root certs are different from client certs even if some (perhaps many or most) client certs were signed by an enterprise root. A client cert is about providing identity information/proofs (instead of or in addition to traditional credentials). I hope mozilla isn't conflating the two though I can see how they might decide that turning on one thing gets you the other as well.
- lawnchair_larry 6y agoCould you not just copy the cert from keychain to firefox’s cert store?
- ggreer 6y agoThat's possible, but the certs expire very quickly and they only offer access to a tiny subset of resources. You'd be constantly exporting & importing certs.
- nbadg 6y agoNot necessarily; it's possible for the certs to be copy protected.
- lawnchair_larry 6y agoNo it isn’t.